<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Plugin — PoC Archive</title><link>https://poc.intelseclab.com/tags/plugin/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 16 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/plugin/index.xml" rel="self" type="application/rss+xml"/><item><title>Apache Traffic Server Internal @Header Metadata Spoofing (CVE-2026-33267)</title><link>https://poc.intelseclab.com/pocs/web/2026-08-16_cve-2026-33267-apache-trafficserver-header-spoof/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-16_cve-2026-33267-apache-trafficserver-header-spoof/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-33267 / GHSA-jrh6-9hgv-mqm7. Status: Patched (9.2.15 / 10.1.4). Affects: Apache Traffic Server. Tags: apache, traffic-server, ats, header-injection, metadata-spoof, cache-poisoning, acl-bypass, plugin, CVE-2026-33267.</description><category>web</category><category>Critical</category><category>apache</category><category>traffic-server</category><category>ats</category><category>header-injection</category><category>metadata-spoof</category><category>cache-poisoning</category><category>acl-bypass</category><category>plugin</category><category>CVE-2026-33267</category></item><item><title>YayMail WooCommerce Plugin Missing Authorization to Privilege Escalation — CVE-2026-1937</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1937-yaymail-woocommerce-privesc/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1937-yaymail-woocommerce-privesc/</guid><description>High severity (CVSS 7.2) — web · CVE-2026-1937. Status: Weaponized. Affects: YayMail – WooCommerce Email Customizer plugin for WordPress. Tags: wordpress, woocommerce, plugin, missing-authorization, privilege-escalation, mass-exploitation, ajax.</description><category>web</category><category>High</category><category>wordpress</category><category>woocommerce</category><category>plugin</category><category>missing-authorization</category><category>privilege-escalation</category><category>mass-exploitation</category><category>ajax</category></item><item><title>WP Captcha PRO Subscriber-to-Administrator Authentication Bypass — CVE-2026-5415</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5415-wp-captcha-pro-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5415-wp-captcha-pro-auth-bypass/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-5415. Status: PoC. Affects: WP Captcha PRO (WordPress plugin, Advanced Google reCAPTCHA). Tags: wordpress, wp-captcha-pro, auth-bypass, privilege-escalation, nonce, ajax, account-takeover, plugin.</description><category>web</category><category>High</category><category>wordpress</category><category>wp-captcha-pro</category><category>auth-bypass</category><category>privilege-escalation</category><category>nonce</category><category>ajax</category><category>account-takeover</category><category>plugin</category></item><item><title>WordPress Contest Gallery Plugin Unauthenticated Blind SQL Injection — CVE-2026-3180</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3180-contest-gallery-blind-sqli/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3180-contest-gallery-blind-sqli/</guid><description>High severity — web · CVE-2026-3180. Status: PoC. Affects: WordPress "Contest Gallery" plugin. Tags: wordpress, sqli, blind-sqli, plugin, admin-ajax, unauthenticated, php, boolean-based.</description><category>web</category><category>High</category><category>wordpress</category><category>sqli</category><category>blind-sqli</category><category>plugin</category><category>admin-ajax</category><category>unauthenticated</category><category>php</category><category>boolean-based</category></item><item><title>WordPress "Import and Export Users and Customers" Plugin Privilege Escalation (CVE-2026-3629)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3629-wordpress-privilege-escalation/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3629-wordpress-privilege-escalation/</guid><description>Critical severity — web · CVE-2026-3629. Status: PoC. Affects: Import and Export Users and Customers (WordPress plugin). Tags: wordpress, privilege-escalation, plugin, import-export-users, cwe-269.</description><category>web</category><category>Critical</category><category>wordpress</category><category>privilege-escalation</category><category>plugin</category><category>import-export-users</category><category>cwe-269</category></item><item><title>WooCommerce Wholesale Lead Capture — Unauthenticated Privilege Escalation &amp; File Upload RCE (CVE-2026-27542 / CVE-2026-27540)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27542-woocommerce-wwlc-privesc-fileupload/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-27542-woocommerce-wwlc-privesc-fileupload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-27542 (bundled with CVE-2026-27540). Status: Weaponized. Affects: WooCommerce Wholesale Lead Capture (WWLC) plugin for WordPress. Tags: wordpress, woocommerce, plugin, privilege-escalation, file-upload, rce, unauthenticated, mass-scanning.</description><category>web</category><category>Critical</category><category>wordpress</category><category>woocommerce</category><category>plugin</category><category>privilege-escalation</category><category>file-upload</category><category>rce</category><category>unauthenticated</category><category>mass-scanning</category></item><item><title>UpdraftPlus WordPress Plugin — Unauthenticated RPC Key Bypass to Admin Creation &amp; RCE (CVE-2026-10795)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-10795-updraftplus-rpc-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-10795-updraftplus-rpc-rce/</guid><description>Critical severity — web · CVE-2026-10795. Status: Weaponized. Affects: UpdraftPlus (WordPress backup plugin) — UpdraftCentral remote RPC feature. Tags: wordpress, plugin, updraftplus, rpc, unauthenticated, admin-takeover, plugin-upload, rce, mass-exploitation.</description><category>web</category><category>Critical</category><category>wordpress</category><category>plugin</category><category>updraftplus</category><category>rpc</category><category>unauthenticated</category><category>admin-takeover</category><category>plugin-upload</category><category>rce</category><category>mass-exploitation</category></item><item><title>Snow Monkey Forms — Unauthenticated Arbitrary File Deletion via Path Traversal (CVE-2026-1056)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1056-snow-monkey-forms-file-deletion/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1056-snow-monkey-forms-file-deletion/</guid><description>Critical severity — web · CVE-2026-1056. Status: PoC. Affects: Snow Monkey Forms (WordPress plugin). Tags: wordpress, plugin, snow-monkey-forms, path-traversal, file-deletion, unauthenticated, rest-api, csrf-bypass.</description><category>web</category><category>Critical</category><category>wordpress</category><category>plugin</category><category>snow-monkey-forms</category><category>path-traversal</category><category>file-deletion</category><category>unauthenticated</category><category>rest-api</category><category>csrf-bypass</category></item><item><title>Simple File List Plugin Unauthenticated File Modification / Path Traversal — CVE-2026-11912</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-11912-simple-file-list-path-traversal/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-11912-simple-file-list-path-traversal/</guid><description>High severity (CVSS 7.5) — web · CVE-2026-11912. Status: PoC. Affects: Simple File List WordPress plugin. Tags: wordpress, plugin, path-traversal, missing-authorization, unauthenticated, file-deletion, ajax, nonce.</description><category>web</category><category>High</category><category>wordpress</category><category>plugin</category><category>path-traversal</category><category>missing-authorization</category><category>unauthenticated</category><category>file-deletion</category><category>ajax</category><category>nonce</category></item><item><title>Prodigy Commerce WordPress Plugin — Unauthenticated Local File Inclusion (CVE-2026-0926)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0926-prodigy-commerce-lfi/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0926-prodigy-commerce-lfi/</guid><description>High severity — web · CVE-2026-0926. Status: PoC. Affects: Prodigy Commerce (WordPress plugin). Tags: wordpress, plugin, prodigy-commerce, lfi, local-file-inclusion, unauthenticated, ajax.</description><category>web</category><category>High</category><category>wordpress</category><category>plugin</category><category>prodigy-commerce</category><category>lfi</category><category>local-file-inclusion</category><category>unauthenticated</category><category>ajax</category></item><item><title>Perfmatters WordPress Plugin Arbitrary File Deletion (CVE-2026-4350)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4350-perfmatters-file-deletion/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4350-perfmatters-file-deletion/</guid><description>High severity (CVSS 8.1) — web · CVE-2026-4350. Status: PoC. Affects: Perfmatters WordPress plugin. Tags: wordpress, plugin, perfmatters, path-traversal, arbitrary-file-deletion, admin-ajax, dos, nuclei.</description><category>web</category><category>High</category><category>wordpress</category><category>plugin</category><category>perfmatters</category><category>path-traversal</category><category>arbitrary-file-deletion</category><category>admin-ajax</category><category>dos</category><category>nuclei</category></item><item><title>NextScripts Social Networks Auto-Poster — WordPress Stored XSS (CVE-2026-3228)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3228-nextscripts-wp-stored-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3228-nextscripts-wp-stored-xss/</guid><description>Medium severity (CVSS 6.4) — web · CVE-2026-3228. Status: PoC. Affects: NextScripts: Social Networks Auto-Poster (WordPress plugin). Tags: wordpress, xss, stored-xss, plugin, contributor-privilege, shortcode, session-hijacking.</description><category>web</category><category>Medium</category><category>wordpress</category><category>xss</category><category>stored-xss</category><category>plugin</category><category>contributor-privilege</category><category>shortcode</category><category>session-hijacking</category></item><item><title>LatePoint Calendar Booking Plugin Contributor-to-Administrator Privilege Escalation (CVE-2026-49083)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49083-latepoint-privilege-escalation/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49083-latepoint-privilege-escalation/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-49083. Status: PoC. Affects: LatePoint Calendar Booking plugin for WordPress. Tags: wordpress, latepoint, privilege-escalation, plugin, ajax, python, authenticated.</description><category>web</category><category>High</category><category>wordpress</category><category>latepoint</category><category>privilege-escalation</category><category>plugin</category><category>ajax</category><category>python</category><category>authenticated</category></item><item><title>LA-Studio Element Kit for Elementor — Unauthenticated Admin Account Creation (CVE-2026-0920)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0920-lakit-elementor-privesc/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0920-lakit-elementor-privesc/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-0920. Status: Weaponized. Affects: LA-Studio Element Kit for Elementor (WordPress plugin, slug lakit). Tags: wordpress, plugin, elementor, privilege-escalation, admin-takeover, unauthenticated, ajax, wp-ajax.</description><category>web</category><category>Critical</category><category>wordpress</category><category>plugin</category><category>elementor</category><category>privilege-escalation</category><category>admin-takeover</category><category>unauthenticated</category><category>ajax</category><category>wp-ajax</category></item><item><title>Hustle (WordPress Popup) Authenticated Arbitrary File Upload via Module Import (CVE-2026-0911)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0911-hustle-wordpress-upload/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0911-hustle-wordpress-upload/</guid><description>High severity — web · CVE-2026-0911. Status: PoC. Affects: Hustle (wordpress-popup) plugin by WPMU DEV. Tags: wordpress, hustle, plugin, file-upload, rce, wp_handle_upload, orphan-file, authenticated, cwe-434.</description><category>web</category><category>High</category><category>wordpress</category><category>hustle</category><category>plugin</category><category>file-upload</category><category>rce</category><category>wp_handle_upload</category><category>orphan-file</category><category>authenticated</category><category>cwe-434</category></item><item><title>Hippoo Mobile App for WooCommerce — Unauthenticated Admin Account Takeover (CVE-2026-10580)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-10580-hippoo-woocommerce-authbypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-10580-hippoo-woocommerce-authbypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-10580. Status: Weaponized. Affects: Hippoo Mobile App for WooCommerce (WordPress plugin). Tags: wordpress, plugin, woocommerce, hippoo, authentication-bypass, account-takeover, rest-api, unauthenticated.</description><category>web</category><category>Critical</category><category>wordpress</category><category>plugin</category><category>woocommerce</category><category>hippoo</category><category>authentication-bypass</category><category>account-takeover</category><category>rest-api</category><category>unauthenticated</category></item><item><title>ElementsKit Elementor Addons Authenticated Stored XSS via REST API (CVE-2026-2600)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-2600-elementskit-stored-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-2600-elementskit-stored-xss/</guid><description>Medium severity (CVSS 6.4) — web · CVE-2026-2600. Status: Weaponized. Affects: ElementsKit Elementor Addons (WordPress plugin). Tags: wordpress, elementor, stored-xss, rest-api, privilege-escalation, contributor, plugin, cwe-79.</description><category>web</category><category>Medium</category><category>wordpress</category><category>elementor</category><category>stored-xss</category><category>rest-api</category><category>privilege-escalation</category><category>contributor</category><category>plugin</category><category>cwe-79</category></item><item><title>Branda White Label &amp; Branding Plugin Unauthenticated Account Takeover — CVE-2026-11551</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-11551-branda-wp-account-takeover/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-11551-branda-wp-account-takeover/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-11551. Status: Weaponized. Affects: Branda White Label &amp; Branding WordPress plugin. Tags: wordpress, plugin, account-takeover, privilege-escalation, unauthenticated, multisite, branda.</description><category>web</category><category>Critical</category><category>wordpress</category><category>plugin</category><category>account-takeover</category><category>privilege-escalation</category><category>unauthenticated</category><category>multisite</category><category>branda</category></item></channel></rss>