<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cwe-434 — PoC Archive</title><link>https://poc.intelseclab.com/tags/cwe-434/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 27 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/cwe-434/index.xml" rel="self" type="application/rss+xml"/><item><title>Joomla Balbooa Forms Unauthenticated Arbitrary File Upload → RCE (CVE-2026-56291)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-56291-joomla-balbooa-forms-file-upload-rce/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-56291-joomla-balbooa-forms-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-56291. Status: Weaponized. Affects: Balbooa Forms (com_baforms) — third-party Joomla! extension by balbooa.com. Tags: joomla, balbooa-forms, file-upload, webshell, unauthenticated, rce, kev, actively-exploited, cwe-434.</description><category>web</category><category>Critical</category><category>joomla</category><category>balbooa-forms</category><category>file-upload</category><category>webshell</category><category>unauthenticated</category><category>rce</category><category>kev</category><category>actively-exploited</category><category>cwe-434</category></item><item><title>Unauthenticated Arbitrary File Upload RCE in iCagenda for Joomla (CVE-2026-48939)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-48939-icagenda-joomla-file-upload-rce/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-48939-icagenda-joomla-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-48939. Status: Weaponized (public PoC available, actively exploited in the wild, in CISA KEV since 2026-07-10). Affects: iCagenda — events/calendar extension (component) for Joomla. Tags: joomla, icagenda, file-upload, rce, cwe-434, unauthenticated, remote, kev, cms, php, access-control-bypass.</description><category>web</category><category>Critical</category><category>joomla</category><category>icagenda</category><category>file-upload</category><category>rce</category><category>cwe-434</category><category>unauthenticated</category><category>remote</category><category>kev</category><category>cms</category><category>php</category><category>access-control-bypass</category></item><item><title>WP移行専用プラグイン for CPI &lt;= 1.0.2 - Unauthenticated Arbitrary File Upload RCE (CVE-2025-11170)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-11170-cpi-plugin-file-upload-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-11170-cpi-plugin-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-11170. Status: Weaponized. Affects: WP移行専用プラグイン for CPI (cpi-wp-migration, a CPI/site-migration import plugin for WordPress). Tags: wordpress, cpi-wp-migration, unauthenticated-file-upload, rce, admin-ajax, cwe-434, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>cpi-wp-migration</category><category>unauthenticated-file-upload</category><category>rce</category><category>admin-ajax</category><category>cwe-434</category><category>python</category></item><item><title>WordPress WPAMS Plugin Arbitrary File Upload to RCE (CVE-2025-39401)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-39401-wpams-arbitrary-file-upload-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-39401-wpams-arbitrary-file-upload-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-39401. Status: Weaponized. Affects: WPAMS (WordPress Apartment/Property Management System) plugin by mojoomla. Tags: wordpress, wpams, mojoomla, arbitrary-file-upload, webshell, rce, unauthenticated, python, multithreaded, cwe-434.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wpams</category><category>mojoomla</category><category>arbitrary-file-upload</category><category>webshell</category><category>rce</category><category>unauthenticated</category><category>python</category><category>multithreaded</category><category>cwe-434</category></item><item><title>WooCommerce Dynamic Pricing &amp; Discounts (WC Designer Pro) Unauthenticated File Upload RCE (CVE-2025-6440)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6440-woocommerce-dynamic-pricing-file-upload-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6440-woocommerce-dynamic-pricing-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-6440. Status: Weaponized. Affects: WordPress WooCommerce Dynamic Pricing &amp; Discounts plugin (wc-designer-pro). Tags: wordpress, woocommerce, wc-designer-pro, dynamic-pricing, file-upload, rce, unauthenticated, wp-ajax, cwe-434, nuclei.</description><category>web</category><category>Critical</category><category>wordpress</category><category>woocommerce</category><category>wc-designer-pro</category><category>dynamic-pricing</category><category>file-upload</category><category>rce</category><category>unauthenticated</category><category>wp-ajax</category><category>cwe-434</category><category>nuclei</category></item><item><title>Webkul Medical Prescription Attachment for WooCommerce — Unrestricted File Upload to Web Shell (CVE-2025-29009)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-29009-woocommerce-medical-prescription-file-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-29009-woocommerce-medical-prescription-file-upload/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-29009. Status: Weaponized. Affects: Webkul "Medical Prescription Attachment Plugin for WooCommerce" (WordPress plugin). Tags: wordpress, woocommerce, medical-prescription-attachment, unrestricted-file-upload, webshell, cwe-434, unauthenticated, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>woocommerce</category><category>medical-prescription-attachment</category><category>unrestricted-file-upload</category><category>webshell</category><category>cwe-434</category><category>unauthenticated</category><category>python</category></item><item><title>StoryChief WordPress Plugin Unauthenticated Arbitrary File Upload via Webhook (CVE-2025-7441)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-7441-storychief-webhook-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-7441-storychief-webhook-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-7441. Status: PoC. Affects: StoryChief WordPress plugin. Tags: storychief, wordpress, wordpress-plugin, arbitrary-file-upload, ssrf, remote-code-execution, unauthenticated, webhook, hmac, cwe-434, python.</description><category>web</category><category>Critical</category><category>storychief</category><category>wordpress</category><category>wordpress-plugin</category><category>arbitrary-file-upload</category><category>ssrf</category><category>remote-code-execution</category><category>unauthenticated</category><category>webhook</category><category>hmac</category><category>cwe-434</category><category>python</category></item><item><title>StoreKeeper for WooCommerce Unauthenticated Arbitrary File Upload (CVE-2025-48148)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-48148-storekeeper-woocommerce-webshell-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-48148-storekeeper-woocommerce-webshell-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-48148. Status: Weaponized. Affects: StoreKeeper for WooCommerce (WordPress plugin). Tags: wordpress, woocommerce, storekeeper, arbitrary-file-upload, unauthenticated, webshell, rce, cwe-434, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>woocommerce</category><category>storekeeper</category><category>arbitrary-file-upload</category><category>unauthenticated</category><category>webshell</category><category>rce</category><category>cwe-434</category><category>python</category></item><item><title>SAP NetWeaver Visual Composer Unrestricted File Upload RCE (CVE-2025-31324)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-31324-sap-netweaver-visual-composer-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-31324-sap-netweaver-visual-composer-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-31324. Status: Weaponized. Affects: SAP NetWeaver Application Server (AS) Java — Visual Composer component (VCFRAMEWORK), specifically the Metadata Uploader servlet. Tags: sap-netweaver, visual-composer, metadatauploader, unrestricted-file-upload, java-deserialization, jsp-webshell, rce, cwe-434, cwe-502, python.</description><category>web</category><category>Critical</category><category>sap-netweaver</category><category>visual-composer</category><category>metadatauploader</category><category>unrestricted-file-upload</category><category>java-deserialization</category><category>jsp-webshell</category><category>rce</category><category>cwe-434</category><category>cwe-502</category><category>python</category></item><item><title>Samsung MagicINFO 9 Server Unauthenticated Path Traversal to RCE (CVE-2025-4632)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-4632-magicinfo-path-traversal-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-4632-magicinfo-path-traversal-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-4632. Status: Weaponized. Affects: Samsung MagicINFO 9 Server (digital signage content management server), SWUpdateFileUploader servlet. Tags: samsung, magicinfo, path-traversal, arbitrary-file-upload, unauthenticated-rce, jsp-webshell, cwe-22, cwe-434, python.</description><category>web</category><category>Critical</category><category>samsung</category><category>magicinfo</category><category>path-traversal</category><category>arbitrary-file-upload</category><category>unauthenticated-rce</category><category>jsp-webshell</category><category>cwe-22</category><category>cwe-434</category><category>python</category></item><item><title>Podlove Podcast Publisher &lt;= 4.2.6 - Unauthenticated Arbitrary File Upload RCE (CVE-2025-10147)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-10147-podlove-podcast-publisher-file-upload-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-10147-podlove-podcast-publisher-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-10147. Status: Weaponized. Affects: Podlove Podcast Publisher (WordPress plugin). Tags: wordpress, podlove, podcast-publisher, unauthenticated-file-upload, rce, cwe-434, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>podlove</category><category>podcast-publisher</category><category>unauthenticated-file-upload</category><category>rce</category><category>cwe-434</category><category>python</category></item><item><title>Monsta FTP Pre-Authentication Remote Code Execution via Arbitrary File Upload (CVE-2025-34299)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-34299-monsta-ftp-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-34299-monsta-ftp-rce/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-34299. Status: Weaponized. Affects: Monsta FTP (web-based FTP manager). Tags: monsta-ftp, rce, pre-auth, unrestricted-file-upload, cwe-434, php, ftp, docker, nuclei, kev.</description><category>network</category><category>Critical</category><category>monsta-ftp</category><category>rce</category><category>pre-auth</category><category>unrestricted-file-upload</category><category>cwe-434</category><category>php</category><category>ftp</category><category>docker</category><category>nuclei</category><category>kev</category></item><item><title>Flozen WordPress Theme Unauthenticated Arbitrary File Upload (CVE-2025-49071)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-49071-flozen-theme-arbitrary-file-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-49071-flozen-theme-arbitrary-file-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-49071. Status: Weaponized. Affects: Flozen Theme for WordPress. Tags: wordpress, flozen-theme, arbitrary-file-upload, unauthenticated, webshell, zip-upload, rce, cwe-434, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>flozen-theme</category><category>arbitrary-file-upload</category><category>unauthenticated</category><category>webshell</category><category>zip-upload</category><category>rce</category><category>cwe-434</category><category>python</category></item><item><title>Cibeles AI `actualizador_git.php` Unauthenticated Arbitrary File Upload / RCE (CVE-2025-13595)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13595-cibeles-ai-file-upload-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13595-cibeles-ai-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-13595. Status: Weaponized. Affects: Cibeles AI (WordPress plugin). Tags: wordpress, cibeles-ai, unauthenticated-file-upload, github-mirror-abuse, webshell, python, cwe-434, cwe-306.</description><category>web</category><category>Critical</category><category>wordpress</category><category>cibeles-ai</category><category>unauthenticated-file-upload</category><category>github-mirror-abuse</category><category>webshell</category><category>python</category><category>cwe-434</category><category>cwe-306</category></item><item><title>AI Feeds `actualizador_git.php` Unauthenticated Arbitrary File Upload / RCE (CVE-2025-13597)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13597-ai-feeds-file-upload-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13597-ai-feeds-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-13597. Status: Weaponized. Affects: AI Feeds (WordPress plugin). Tags: wordpress, ai-feeds, unauthenticated-file-upload, github-mirror-abuse, webshell, python, cwe-434, cwe-306.</description><category>web</category><category>Critical</category><category>wordpress</category><category>ai-feeds</category><category>unauthenticated-file-upload</category><category>github-mirror-abuse</category><category>webshell</category><category>python</category><category>cwe-434</category><category>cwe-306</category></item><item><title>Adobe Magento "SessionReaper" Unauthenticated File Upload / LFI (CVE-2025-54236)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-54236-magento-sessionreaper-lfi/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-54236-magento-sessionreaper-lfi/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2025-54236. Status: PoC. Affects: Adobe Commerce / Magento Open Source — customer/address_file/upload endpoint (dubbed "SessionReaper"). Tags: magento, adobe-commerce, sessionreaper, file-upload, lfi, customer-address, form-key, cwe-434, python.</description><category>web</category><category>Critical</category><category>magento</category><category>adobe-commerce</category><category>sessionreaper</category><category>file-upload</category><category>lfi</category><category>customer-address</category><category>form-key</category><category>cwe-434</category><category>python</category></item><item><title>WordPress Ninja Forms Plugin Unauthenticated File Upload — CVE-2026-0740</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0740-ninja-forms-file-upload/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0740-ninja-forms-file-upload/</guid><description>High severity — web · CVE-2026-0740. Status: PoC. Affects: WordPress "Ninja Forms" plugin — file upload field/module. Tags: wordpress, ninja-forms, file-upload, webshell, admin-ajax, plugin-vulnerability, cwe-434.</description><category>web</category><category>High</category><category>wordpress</category><category>ninja-forms</category><category>file-upload</category><category>webshell</category><category>admin-ajax</category><category>plugin-vulnerability</category><category>cwe-434</category></item><item><title>WordPress "Drag and Drop File Upload for Contact Form 7" Unauthenticated RCE — CVE-2026-5364</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5364-cf7-dnd-upload-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5364-cf7-dnd-upload-rce/</guid><description>High severity (CVSS 8.1) — web · CVE-2026-5364. Status: PoC. Affects: WordPress plugin "Drag and Drop File Upload for Contact Form 7" (drag-and-drop-file-upload-for-contact-form-7). Tags: wordpress, contact-form-7, file-upload, webshell, rce, sanitize-file-name-bypass, admin-ajax, cwe-434.</description><category>web</category><category>High</category><category>wordpress</category><category>contact-form-7</category><category>file-upload</category><category>webshell</category><category>rce</category><category>sanitize-file-name-bypass</category><category>admin-ajax</category><category>cwe-434</category></item><item><title>WebStack WordPress Theme Unauthenticated Arbitrary File Upload RCE — CVE-2026-1555</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1555-webstack-wp-file-upload-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1555-webstack-wp-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-1555. Status: Weaponized. Affects: WebStack theme for WordPress. Tags: wordpress, webstack-theme, arbitrary-file-upload, unauthenticated-rce, webshell, ajax, cwe-434.</description><category>web</category><category>Critical</category><category>wordpress</category><category>webstack-theme</category><category>arbitrary-file-upload</category><category>unauthenticated-rce</category><category>webshell</category><category>ajax</category><category>cwe-434</category></item><item><title>Visitor Management System 1.0 — Unrestricted File Upload to RCE (CVE-2026-37748)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37748-visitor-management-system-file-upload-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37748-visitor-management-system-file-upload-rce/</guid><description>High severity (CVSS 7.2) — web · CVE-2026-37748. Status: PoC. Affects: Visitor Management System (sanjay1313) 1.0. Tags: php, unrestricted-file-upload, rce, webshell, admin-authenticated, cwe-434.</description><category>web</category><category>High</category><category>php</category><category>unrestricted-file-upload</category><category>rce</category><category>webshell</category><category>admin-authenticated</category><category>cwe-434</category></item><item><title>Veno File Manager Arbitrary PHP File Overwrite (CVE-2026-37068)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37068-veno-file-manager-arbitrary-file-write/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-37068-veno-file-manager-arbitrary-file-write/</guid><description>Critical severity — web · CVE-2026-37068. Status: Weaponized. Affects: Veno File Manager Project. Tags: veno-file-manager, arbitrary-file-write, rce, authenticated, superadmin, cwe-434.</description><category>web</category><category>Critical</category><category>veno-file-manager</category><category>arbitrary-file-write</category><category>rce</category><category>authenticated</category><category>superadmin</category><category>cwe-434</category></item><item><title>Schema &amp; Structured Data for WP &amp; AMP Unauthenticated Unrestricted File Upload (CVE-2026-9067)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-9067-schema-structured-data-file-upload/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-9067-schema-structured-data-file-upload/</guid><description>High severity (CVSS 8.1) — web · CVE-2026-9067. Status: PoC. Affects: Schema &amp; Structured Data for WP &amp; AMP (WordPress plugin, schema-and-structured-data-for-wp). Tags: wordpress, unrestricted-file-upload, cwe-434, ajax, unauthenticated, content-hosting.</description><category>web</category><category>High</category><category>wordpress</category><category>unrestricted-file-upload</category><category>cwe-434</category><category>ajax</category><category>unauthenticated</category><category>content-hosting</category></item><item><title>midi-Synth WordPress Plugin Arbitrary File Upload (CVE-2026-1306)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1306-wp-midi-synth-file-upload/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1306-wp-midi-synth-file-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-1306. Status: Weaponized. Affects: midi-Synth WordPress plugin. Tags: wordpress, wp-plugin, file-upload, cwe-434, webshell, ajax, mass-scanning.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wp-plugin</category><category>file-upload</category><category>cwe-434</category><category>webshell</category><category>ajax</category><category>mass-scanning</category></item><item><title>Hustle (WordPress Popup) Authenticated Arbitrary File Upload via Module Import (CVE-2026-0911)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0911-hustle-wordpress-upload/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0911-hustle-wordpress-upload/</guid><description>High severity — web · CVE-2026-0911. Status: PoC. Affects: Hustle (wordpress-popup) plugin by WPMU DEV. Tags: wordpress, hustle, plugin, file-upload, rce, wp_handle_upload, orphan-file, authenticated, cwe-434.</description><category>web</category><category>High</category><category>wordpress</category><category>hustle</category><category>plugin</category><category>file-upload</category><category>rce</category><category>wp_handle_upload</category><category>orphan-file</category><category>authenticated</category><category>cwe-434</category></item><item><title>EventPrime WordPress Plugin Unauthenticated Arbitrary File Upload — CVE-2026-1657</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1657-eventprime-wp-file-upload/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1657-eventprime-wp-file-upload/</guid><description>Medium severity — web · CVE-2026-1657. Status: PoC. Affects: EventPrime (WordPress plugin). Tags: wordpress, eventprime, arbitrary-file-upload, unauthenticated, ajax, media-library, cwe-434.</description><category>web</category><category>Medium</category><category>wordpress</category><category>eventprime</category><category>arbitrary-file-upload</category><category>unauthenticated</category><category>ajax</category><category>media-library</category><category>cwe-434</category></item><item><title>Chamilo LMS Authenticated RCE via Unrestricted File Upload — CVE-2026-29041</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-29041-chamilo-lms-file-upload-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-29041-chamilo-lms-file-upload-rce/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-29041. Status: Weaponized. Affects: Chamilo LMS. Tags: chamilo, lms, file-upload, rce, webshell, cwe-434, mime-bypass, authenticated.</description><category>web</category><category>High</category><category>chamilo</category><category>lms</category><category>file-upload</category><category>rce</category><category>webshell</category><category>cwe-434</category><category>mime-bypass</category><category>authenticated</category></item><item><title>BookingPress Pro Unauthenticated Arbitrary File Upload via Data URI Signature Field (CVE-2026-6960)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-6960-bookingpress-unauth-file-upload/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-6960-bookingpress-unauth-file-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-6960. Status: Weaponized. Affects: BookingPress Pro (WordPress appointment-booking plugin). Tags: wordpress, bookingpress, unauthenticated, file-upload, rce, data-uri, cwe-434.</description><category>web</category><category>Critical</category><category>wordpress</category><category>bookingpress</category><category>unauthenticated</category><category>file-upload</category><category>rce</category><category>data-uri</category><category>cwe-434</category></item><item><title>Bludit CMS API Unrestricted File Upload to RCE (CVE-2026-25099)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25099-bludit-webshell-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25099-bludit-webshell-rce/</guid><description>High severity — web · CVE-2026-25099. Status: Weaponized. Affects: Bludit CMS (/api/files/&lt;page-key> endpoint). Tags: bludit, cms, file-upload, webshell, rce, php, api-token, cwe-434, authenticated.</description><category>web</category><category>High</category><category>bludit</category><category>cms</category><category>file-upload</category><category>webshell</category><category>rce</category><category>php</category><category>api-token</category><category>cwe-434</category><category>authenticated</category></item><item><title>SP Page Builder (Joomla) Unauthenticated File Upload RCE (CVE-2026-48908)</title><link>https://poc.intelseclab.com/pocs/web/2026-06-30_cve-2026-48908-sp-page-builder-joomla-rce/</link><pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-06-30_cve-2026-48908-sp-page-builder-joomla-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-48908 (GHSA-8fwr-8fxr-8v2p). Status: Weaponized — public PoC with mass-scan support, added to CISA KEV 2026-07-07, confirmed active in-the-wild exploitation. Affects: SP Page Builder extension for Joomla (joomshaper.net). Tags: RCE, unauthenticated, file-upload, PHP-webshell, Joomla, CMS, access-control, Python, CVSS-10, kev, backdoor, cwe-434.</description><category>web</category><category>Critical</category><category>RCE</category><category>unauthenticated</category><category>file-upload</category><category>PHP-webshell</category><category>Joomla</category><category>CMS</category><category>access-control</category><category>Python</category><category>CVSS-10</category><category>kev</category><category>backdoor</category><category>cwe-434</category></item></channel></rss>