<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cwe-269 — PoC Archive</title><link>https://poc.intelseclab.com/tags/cwe-269/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 06 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/cwe-269/index.xml" rel="self" type="application/rss+xml"/><item><title>Simple User Registration WordPress Plugin — Unauthenticated Privilege Escalation (CVE-2025-4334)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-4334-simple-user-registration-privesc/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-4334-simple-user-registration-privesc/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-4334. Status: PoC. Affects: "Simple User Registration" WordPress plugin (registration/form-builder plugin, wpr_submit_form AJAX action). Tags: wordpress, wp-plugin, simple-user-registration, privilege-escalation, unauthenticated, admin-ajax, cwe-269, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wp-plugin</category><category>simple-user-registration</category><category>privilege-escalation</category><category>unauthenticated</category><category>admin-ajax</category><category>cwe-269</category><category>python</category></item><item><title>Real Spaces WordPress Theme Unauthenticated Privilege Escalation via `imic_agent_register` (CVE-2025-6758)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6758-realspaces-privesc/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6758-realspaces-privesc/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-6758. Status: Weaponized. Affects: Real Spaces - Properties Directory Theme for WordPress (imic_agent_register AJAX handler). Tags: wordpress, real-spaces, imic, privilege-escalation, unauthenticated, admin-ajax, role-assignment, cwe-269, cwe-863, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>real-spaces</category><category>imic</category><category>privilege-escalation</category><category>unauthenticated</category><category>admin-ajax</category><category>role-assignment</category><category>cwe-269</category><category>cwe-863</category><category>python</category></item><item><title>Opal Estate Pro WordPress Plugin Unauthenticated Administrator Registration (CVE-2025-6934)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6934-opal-estate-admin-register/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6934-opal-estate-admin-register/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-6934. Status: Weaponized. Affects: Opal Estate Pro (WordPress real-estate plugin). Tags: wordpress, opal-estate-pro, privilege-escalation, unauthenticated-registration, admin-ajax, nonce-abuse, cwe-269, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>opal-estate-pro</category><category>privilege-escalation</category><category>unauthenticated-registration</category><category>admin-ajax</category><category>nonce-abuse</category><category>cwe-269</category><category>python</category></item><item><title>Fox LMS `createOrder` Unauthenticated Privilege Escalation to Administrator (CVE-2025-14156)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14156-fox-lms-privilege-escalation/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14156-fox-lms-privilege-escalation/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-14156. Status: Weaponized. Affects: Fox LMS (WordPress LMS plugin). Tags: wordpress, fox-lms, rest-api, privilege-escalation, role-injection, unauthenticated, python, cwe-269.</description><category>web</category><category>Critical</category><category>wordpress</category><category>fox-lms</category><category>rest-api</category><category>privilege-escalation</category><category>role-injection</category><category>unauthenticated</category><category>python</category><category>cwe-269</category></item><item><title>WordPress "Import and Export Users and Customers" Plugin Privilege Escalation (CVE-2026-3629)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3629-wordpress-privilege-escalation/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3629-wordpress-privilege-escalation/</guid><description>Critical severity — web · CVE-2026-3629. Status: PoC. Affects: Import and Export Users and Customers (WordPress plugin). Tags: wordpress, privilege-escalation, plugin, import-export-users, cwe-269.</description><category>web</category><category>Critical</category><category>wordpress</category><category>privilege-escalation</category><category>plugin</category><category>import-export-users</category><category>cwe-269</category></item><item><title>User Registration &amp; Membership Unauthenticated Admin Privilege Escalation (CVE-2026-1492)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1492-user-registration-membership-privesc/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1492-user-registration-membership-privesc/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-1492. Status: Weaponized. Affects: User Registration &amp; Membership WordPress plugin (Custom Registration Form Builder, Login Form, User Profile, Content Restriction &amp; Membership). Tags: wordpress, privilege-escalation, unauthenticated, ajax, membership-plugin, admin-takeover, cwe-269.</description><category>web</category><category>Critical</category><category>wordpress</category><category>privilege-escalation</category><category>unauthenticated</category><category>ajax</category><category>membership-plugin</category><category>admin-takeover</category><category>cwe-269</category></item><item><title>Masteriyo LMS Authenticated Privilege Escalation to Administrator (CVE-2026-4484)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4484-masteriyo-lms-privesc/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4484-masteriyo-lms-privesc/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-4484. Status: PoC. Affects: Masteriyo LMS plugin for WordPress. Tags: wordpress, masteriyo-lms, privilege-escalation, rest-api, cwe-269, broken-access-control.</description><category>web</category><category>High</category><category>wordpress</category><category>masteriyo-lms</category><category>privilege-escalation</category><category>rest-api</category><category>cwe-269</category><category>broken-access-control</category></item><item><title>LatePoint Calendar Booking Plugin Agent-to-Administrator Privilege Escalation — CVE-2026-6741</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-6741-latepoint-privesc/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-6741-latepoint-privesc/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-6741. Status: PoC. Affects: LatePoint – Calendar Booking Plugin for Appointments and Events (WordPress plugin, slug latepoint). Tags: wordpress, latepoint, privilege-escalation, abilities-api, rest-api, account-takeover, cwe-269.</description><category>web</category><category>High</category><category>wordpress</category><category>latepoint</category><category>privilege-escalation</category><category>abilities-api</category><category>rest-api</category><category>account-takeover</category><category>cwe-269</category></item><item><title>Easy Elements for Elementor Unauthenticated Privilege Escalation via `custom_meta` Overwrite (CVE-2026-9018)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-9018-easy-elements-elementor-privesc/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-9018-easy-elements-elementor-privesc/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-9018. Status: PoC. Affects: Easy Elements for Elementor – Addons &amp; Website Templates (easy-elements WordPress plugin). Tags: wordpress, elementor, easy-elements, privilege-escalation, cwe-269, unauthenticated, ajax, wp-capabilities.</description><category>web</category><category>High</category><category>wordpress</category><category>elementor</category><category>easy-elements</category><category>privilege-escalation</category><category>cwe-269</category><category>unauthenticated</category><category>ajax</category><category>wp-capabilities</category></item><item><title>Azuriom CMS Broken Access Control — Account Takeover via AzLink Server Token — CVE-2026-54415</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-54415-azuriom-account-takeover/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-54415-azuriom-account-takeover/</guid><description>High severity (CVSS 3.1) — web · CVE-2026-54415. Status: PoC. Affects: Azuriom CMS. Tags: azuriom, cms, broken-access-control, cwe-862, cwe-269, privilege-escalation, account-takeover, php, laravel, azlink.</description><category>web</category><category>High</category><category>azuriom</category><category>cms</category><category>broken-access-control</category><category>cwe-862</category><category>cwe-269</category><category>privilege-escalation</category><category>account-takeover</category><category>php</category><category>laravel</category><category>azlink</category></item></channel></rss>