PoC Archive PoC Archive

tag

Plugin

Apache Traffic Server Internal @Header Metadata Spoofing (CVE-2026-33267)
CVE-2026-33267 / GHSA-jrh6-9hgv-mqm7 web Patched
CVE-2026-33267 / GHSA-jrh6-9hgv-mqm7webCRITICAL 10Patched2026-08-16YayMail WooCommerce Plugin Missing Authorization to Privilege Escalation — CVE-2026-1937
CVE-2026-1937 web Unverified
CVE-2026-1937webHIGH 7.2Unverified2026-07-05WP Captcha PRO Subscriber-to-Administrator Authentication Bypass — CVE-2026-5415
CVE-2026-5415 web Unverified
CVE-2026-5415webHIGH 8.8Unverified2026-07-05WordPress Contest Gallery Plugin Unauthenticated Blind SQL Injection — CVE-2026-3180
CVE-2026-3180 web Unverified
CVE-2026-3180webHIGHUnverified2026-07-05WordPress "Import and Export Users and Customers" Plugin Privilege Escalation (CVE-2026-3629)
CVE-2026-3629 web Unverified
CVE-2026-3629webCRITICALUnverified2026-07-05WooCommerce Wholesale Lead Capture — Unauthenticated Privilege Escalation & File Upload RCE (CVE-2026-27542 / CVE-2026-27540)
CVE-2026-27542 (bundled with CVE-2026-27540) web Unverified
CVE-2026-27542webCRITICAL 9.8Unverified2026-07-05UpdraftPlus WordPress Plugin — Unauthenticated RPC Key Bypass to Admin Creation & RCE (CVE-2026-10795)
CVE-2026-10795 web Unverified
CVE-2026-10795webCRITICALUnverified2026-07-05Snow Monkey Forms — Unauthenticated Arbitrary File Deletion via Path Traversal (CVE-2026-1056) EPSS 12%
CVE-2026-1056 web Unverified
CVE-2026-1056webCRITICALUnverified2026-07-05Simple File List Plugin Unauthenticated File Modification / Path Traversal — CVE-2026-11912
CVE-2026-11912 web Patched
CVE-2026-11912webHIGH 7.5Patched2026-07-05Prodigy Commerce WordPress Plugin — Unauthenticated Local File Inclusion (CVE-2026-0926)
CVE-2026-0926 web Unverified
CVE-2026-0926webHIGHUnverified2026-07-05Perfmatters WordPress Plugin Arbitrary File Deletion (CVE-2026-4350)
CVE-2026-4350 web Unverified
CVE-2026-4350webHIGH 8.1Unverified2026-07-05NextScripts Social Networks Auto-Poster — WordPress Stored XSS (CVE-2026-3228)
CVE-2026-3228 web Unverified
CVE-2026-3228webMEDIUM 6.4Unverified2026-07-05LatePoint Calendar Booking Plugin Contributor-to-Administrator Privilege Escalation (CVE-2026-49083)
CVE-2026-49083 web Unverified
CVE-2026-49083webHIGH 8.8Unverified2026-07-05LA-Studio Element Kit for Elementor — Unauthenticated Admin Account Creation (CVE-2026-0920)
CVE-2026-0920 web Unverified
CVE-2026-0920webCRITICAL 9.8Unverified2026-07-05Hustle (WordPress Popup) Authenticated Arbitrary File Upload via Module Import (CVE-2026-0911)
CVE-2026-0911 web Unverified
CVE-2026-0911webHIGHUnverified2026-07-05Hippoo Mobile App for WooCommerce — Unauthenticated Admin Account Takeover (CVE-2026-10580)
CVE-2026-10580 web Unverified
CVE-2026-10580webCRITICAL 9.8Unverified2026-07-05ElementsKit Elementor Addons Authenticated Stored XSS via REST API (CVE-2026-2600)
CVE-2026-2600 web Patched
CVE-2026-2600webMEDIUM 6.4Patched2026-07-05Branda White Label & Branding Plugin Unauthenticated Account Takeover — CVE-2026-11551
CVE-2026-11551 web Patched
CVE-2026-11551webCRITICAL 9.8Patched2026-07-05