<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Rest-Api — PoC Archive</title><link>https://poc.intelseclab.com/tags/rest-api/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 09 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/rest-api/index.xml" rel="self" type="application/rss+xml"/><item><title>WordPress — Pre-Auth XSS to RCE Chain via Login Page Parser Differential (CVE-2026-64638, "XSS2Shell")</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-64638-wordpress-xss2shell-pre-auth-xss-to-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-64638-wordpress-xss2shell-pre-auth-xss-to-rce/</guid><description>High severity (CVSS 8.9) — web · CVE-2026-64638. Status: Patched. Affects: WordPress Core, wp-login.php failed-login error message, KSES sanitizer vs PHP strip_tags(). Tags: wordpress, wordpress-core, pre-auth, xss, reflected-xss, xss2shell, rce, parser-differential, dom-clobbering, some, jsonp, rest-api, application-password, plugin-upload, CWE-79, CWE-94, cms.</description><category>web</category><category>High</category><category>wordpress</category><category>wordpress-core</category><category>pre-auth</category><category>xss</category><category>reflected-xss</category><category>xss2shell</category><category>rce</category><category>parser-differential</category><category>dom-clobbering</category><category>some</category><category>jsonp</category><category>rest-api</category><category>application-password</category><category>plugin-upload</category><category>CWE-79</category><category>CWE-94</category><category>cms</category></item><item><title>CVE-2022-40684 — FortiOS / FortiProxy / FortiSwitchManager Authentication Bypass (vamp-forticheck Scanner)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-31_cve-2022-40684-fortios-auth-bypass-scanner/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-31_cve-2022-40684-fortios-auth-bypass-scanner/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2022-40684. Status: Patched (FortiOS ≥7.2.2, ≥7.0.7; FortiProxy ≥7.2.1, ≥7.0.7; FortiSwitchManager ≥7.2.1). Affects: Fortinet FortiOS (FortiGate firewalls), FortiProxy web proxy, FortiSwitchManager web management interface / administrative REST API. Tags: fortios, fortiproxy, fortiswitchmanager, authentication-bypass, rest-api, header-injection, loopback-spoofing, fortigate, ssl-vpn, scanner.</description><category>network</category><category>Critical</category><category>fortios</category><category>fortiproxy</category><category>fortiswitchmanager</category><category>authentication-bypass</category><category>rest-api</category><category>header-injection</category><category>loopback-spoofing</category><category>fortigate</category><category>ssl-vpn</category><category>scanner</category></item><item><title>WordPress Mobile Builder Plugin JWT Authentication Bypass to Admin Account Creation (CVE-2025-68860)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-68860-wp-jwt-admin-forge/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-68860-wp-jwt-admin-forge/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-68860. Status: Weaponized. Affects: WordPress "Mobile Builder" plugin. Tags: wordpress, mobile-builder, jwt, authentication-bypass, hardcoded-secret, privilege-escalation, rest-api, python, cwe-288.</description><category>web</category><category>Critical</category><category>wordpress</category><category>mobile-builder</category><category>jwt</category><category>authentication-bypass</category><category>hardcoded-secret</category><category>privilege-escalation</category><category>rest-api</category><category>python</category><category>cwe-288</category></item><item><title>RestroPress WordPress Plugin Unauthenticated Information Exposure Leading to JWT Forgery / Account Takeover (CVE-2025-9209)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-9209-restropress-jwt-forgery/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-9209-restropress-jwt-forgery/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-9209. Status: Weaponized. Affects: RestroPress – Online Food Ordering System (WordPress plugin). Tags: restropress, wordpress, wordpress-plugin, information-exposure, jwt, authentication-bypass, account-takeover, rest-api, mass-scanner, cwe-200, cwe-287, python.</description><category>web</category><category>Critical</category><category>restropress</category><category>wordpress</category><category>wordpress-plugin</category><category>information-exposure</category><category>jwt</category><category>authentication-bypass</category><category>account-takeover</category><category>rest-api</category><category>mass-scanner</category><category>cwe-200</category><category>cwe-287</category><category>python</category></item><item><title>KiotViet Sync Unauthenticated Arbitrary File Upload (CVE-2025-12674)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12674-kiotviet-sync-file-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12674-kiotviet-sync-file-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-12674. Status: Weaponized. Affects: KiotViet Sync (WordPress plugin). Tags: wordpress, kiotviet-sync, arbitrary-file-upload, unauthenticated, rce, rest-api, webshell, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>kiotviet-sync</category><category>arbitrary-file-upload</category><category>unauthenticated</category><category>rce</category><category>rest-api</category><category>webshell</category><category>python</category></item><item><title>HPE OneView `id-pools/executeCommand` OS Command Injection (CVE-2025-37164)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-37164-hpe-oneview-command-injection/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-37164-hpe-oneview-command-injection/</guid><description>Critical severity (CVSS 10) — network · CVE-2025-37164. Status: PoC. Affects: HPE OneView (infrastructure management appliance) REST API. Tags: hpe-oneview, command-injection, os-command-execution, rce, rest-api, python, cwe-78.</description><category>network</category><category>Critical</category><category>hpe-oneview</category><category>command-injection</category><category>os-command-execution</category><category>rce</category><category>rest-api</category><category>python</category><category>cwe-78</category></item><item><title>Fox LMS `createOrder` Unauthenticated Privilege Escalation to Administrator (CVE-2025-14156)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14156-fox-lms-privilege-escalation/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14156-fox-lms-privilege-escalation/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-14156. Status: Weaponized. Affects: Fox LMS (WordPress LMS plugin). Tags: wordpress, fox-lms, rest-api, privilege-escalation, role-injection, unauthenticated, python, cwe-269.</description><category>web</category><category>Critical</category><category>wordpress</category><category>fox-lms</category><category>rest-api</category><category>privilege-escalation</category><category>role-injection</category><category>unauthenticated</category><category>python</category><category>cwe-269</category></item><item><title>AI Engine WordPress Plugin Unauthenticated MCP Token Disclosure to Admin Account Creation (CVE-2025-11749)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-11749-ai-engine-admin-account-creation/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-11749-ai-engine-admin-account-creation/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-11749. Status: Weaponized. Affects: AI Engine plugin for WordPress (mwai). Tags: wordpress, ai-engine, mwai, mcp, rest-api, information-disclosure, privilege-escalation, admin-account-creation, python, mass-scanner.</description><category>web</category><category>Critical</category><category>wordpress</category><category>ai-engine</category><category>mwai</category><category>mcp</category><category>rest-api</category><category>information-disclosure</category><category>privilege-escalation</category><category>admin-account-creation</category><category>python</category><category>mass-scanner</category></item><item><title>WordPress "List Site Contributors" Plugin Reflected XSS Scanner (CVE-2026-0594)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0594-listsitecontributors-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0594-listsitecontributors-xss/</guid><description>Medium severity — web · CVE-2026-0594. Status: PoC. Affects: "List Site Contributors" WordPress plugin. Tags: wordpress, xss, reflected-xss, wp-json, rest-api, plugin-vulnerability, golang, scanner.</description><category>web</category><category>Medium</category><category>wordpress</category><category>xss</category><category>reflected-xss</category><category>wp-json</category><category>rest-api</category><category>plugin-vulnerability</category><category>golang</category><category>scanner</category></item><item><title>The Events Calendar WordPress Plugin Unauthenticated Blind SQL Injection (CVE-2026-49772)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49772-events-calendar-blind-sqli/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49772-events-calendar-blind-sqli/</guid><description>Critical severity (CVSS 9.3) — web · CVE-2026-49772. Status: PoC. Affects: The Events Calendar (WordPress plugin, StellarWP / Liquid Web), experimental tec/v1 REST API. Tags: wordpress, sqli, blind-sqli, rest-api, the-events-calendar, unauthenticated, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>sqli</category><category>blind-sqli</category><category>rest-api</category><category>the-events-calendar</category><category>unauthenticated</category><category>python</category></item><item><title>Tandoor Recipes Authenticated Local File Disclosure via Recipe Import (CVE-2026-25964)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25964-tandoor-recipes-lfi/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-25964-tandoor-recipes-lfi/</guid><description>Medium severity (CVSS 4.9) — web · CVE-2026-25964 (GHSA-6485-jr28-52xx). Status: PoC. Affects: Tandoor Recipes (self-hosted recipe manager, Django-based). Tags: path-traversal, local-file-disclosure, tandoor-recipes, django, rest-api, authenticated, cwe-22, arbitrary-file-read.</description><category>web</category><category>Medium</category><category>path-traversal</category><category>local-file-disclosure</category><category>tandoor-recipes</category><category>django</category><category>rest-api</category><category>authenticated</category><category>cwe-22</category><category>arbitrary-file-read</category></item><item><title>Snow Monkey Forms — Unauthenticated Arbitrary File Deletion via Path Traversal (CVE-2026-1056)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1056-snow-monkey-forms-file-deletion/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1056-snow-monkey-forms-file-deletion/</guid><description>Critical severity — web · CVE-2026-1056. Status: PoC. Affects: Snow Monkey Forms (WordPress plugin). Tags: wordpress, plugin, snow-monkey-forms, path-traversal, file-deletion, unauthenticated, rest-api, csrf-bypass.</description><category>web</category><category>Critical</category><category>wordpress</category><category>plugin</category><category>snow-monkey-forms</category><category>path-traversal</category><category>file-deletion</category><category>unauthenticated</category><category>rest-api</category><category>csrf-bypass</category></item><item><title>Simple History Missing Authorization Account Takeover — CVE-2026-7459</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-7459-poc/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-7459-poc/</guid><description>High severity (CVSS 7.5) — web · CVE-2026-7459. Status: PoC. Affects: Simple History (WordPress plugin). Tags: wordpress, simple-history, broken-access-control, account-takeover, rest-api, password-reset.</description><category>web</category><category>High</category><category>wordpress</category><category>simple-history</category><category>broken-access-control</category><category>account-takeover</category><category>rest-api</category><category>password-reset</category></item><item><title>Masteriyo LMS Authenticated Privilege Escalation to Administrator (CVE-2026-4484)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4484-masteriyo-lms-privesc/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4484-masteriyo-lms-privesc/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-4484. Status: PoC. Affects: Masteriyo LMS plugin for WordPress. Tags: wordpress, masteriyo-lms, privilege-escalation, rest-api, cwe-269, broken-access-control.</description><category>web</category><category>High</category><category>wordpress</category><category>masteriyo-lms</category><category>privilege-escalation</category><category>rest-api</category><category>cwe-269</category><category>broken-access-control</category></item><item><title>LatePoint Calendar Booking Plugin Agent-to-Administrator Privilege Escalation — CVE-2026-6741</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-6741-latepoint-privesc/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-6741-latepoint-privesc/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-6741. Status: PoC. Affects: LatePoint – Calendar Booking Plugin for Appointments and Events (WordPress plugin, slug latepoint). Tags: wordpress, latepoint, privilege-escalation, abilities-api, rest-api, account-takeover, cwe-269.</description><category>web</category><category>High</category><category>wordpress</category><category>latepoint</category><category>privilege-escalation</category><category>abilities-api</category><category>rest-api</category><category>account-takeover</category><category>cwe-269</category></item><item><title>Kirki WordPress Plugin Password-Reset Hijack Leading to Account Takeover (CVE-2026-8206)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-8206-kirki-password-reset-takeover/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-8206-kirki-password-reset-takeover/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-8206. Status: PoC. Affects: Kirki (WordPress Customizer framework plugin) — CompLibFormHandler REST API endpoint. Tags: wordpress, kirki, account-takeover, password-reset-hijack, unauthenticated, rest-api.</description><category>web</category><category>Critical</category><category>wordpress</category><category>kirki</category><category>account-takeover</category><category>password-reset-hijack</category><category>unauthenticated</category><category>rest-api</category></item><item><title>Hippoo Mobile App for WooCommerce — Unauthenticated Admin Account Takeover (CVE-2026-10580)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-10580-hippoo-woocommerce-authbypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-10580-hippoo-woocommerce-authbypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-10580. Status: Weaponized. Affects: Hippoo Mobile App for WooCommerce (WordPress plugin). Tags: wordpress, plugin, woocommerce, hippoo, authentication-bypass, account-takeover, rest-api, unauthenticated.</description><category>web</category><category>Critical</category><category>wordpress</category><category>plugin</category><category>woocommerce</category><category>hippoo</category><category>authentication-bypass</category><category>account-takeover</category><category>rest-api</category><category>unauthenticated</category></item><item><title>ElementsKit Elementor Addons Authenticated Stored XSS via REST API (CVE-2026-2600)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-2600-elementskit-stored-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-2600-elementskit-stored-xss/</guid><description>Medium severity (CVSS 6.4) — web · CVE-2026-2600. Status: Weaponized. Affects: ElementsKit Elementor Addons (WordPress plugin). Tags: wordpress, elementor, stored-xss, rest-api, privilege-escalation, contributor, plugin, cwe-79.</description><category>web</category><category>Medium</category><category>wordpress</category><category>elementor</category><category>stored-xss</category><category>rest-api</category><category>privilege-escalation</category><category>contributor</category><category>plugin</category><category>cwe-79</category></item></channel></rss>