<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Route-Confusion — PoC Archive</title><link>https://poc.intelseclab.com/tags/route-confusion/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 19 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/route-confusion/index.xml" rel="self" type="application/rss+xml"/><item><title>wp2shell — WordPress Core Pre-Auth SQLi → Row Forgery → Admin Creation → RCE (CVE-2026-63030 + CVE-2026-60137)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-63030-cve-2026-60137-wp2shell-wordpress-core-preauth-rce/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-63030-cve-2026-60137-wp2shell-wordpress-core-preauth-rce/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2026-63030 (REST /batch/v1 route confusion, CVSS 7.5), CVE-2026-60137 (author__not_in SQL injection, CVSS 9.1); GHSA-ff9f-jf42-662q, GHSA-fpp7-x2x2-2mjf. Status: Weaponized — full pre-auth RCE confirmed against stock-default WordPress core, no plugins/misconfiguration required. Affects: WordPress core (REST API /batch/v1, WP_Query::author__not_in). Tags: wordpress, wp-core, sql-injection, route-confusion, cwe-89, cwe-436, unauthenticated, remote, privilege-escalation, rce, oembed, changeset.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wp-core</category><category>sql-injection</category><category>route-confusion</category><category>cwe-89</category><category>cwe-436</category><category>unauthenticated</category><category>remote</category><category>privilege-escalation</category><category>rce</category><category>oembed</category><category>changeset</category></item><item><title>LiteLLM Proxy Unauthenticated Auth Bypass via Host-Header Route Confusion (CVE-2026-49468)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49468-litellm-host-header-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49468-litellm-host-header-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-49468. Status: PoC. Affects: LiteLLM (BerriAI) proxy. Tags: litellm, llm-proxy, auth-bypass, host-header, route-confusion, cwe-290, fastapi, starlette, python.</description><category>web</category><category>Critical</category><category>litellm</category><category>llm-proxy</category><category>auth-bypass</category><category>host-header</category><category>route-confusion</category><category>cwe-290</category><category>fastapi</category><category>starlette</category><category>python</category></item><item><title>Discourse Scoped API Key Pre-Route Authorization Bypass</title><link>https://poc.intelseclab.com/pocs/web/2026-07-03_discourse-scoped-api-key-route-bypass/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-03_discourse-scoped-api-key-route-bypass/</guid><description>High severity — web · None assigned as of 2026-07-03. Status: PoC. Affects: Discourse (forum platform). Tags: discourse, authorization-bypass, api-key-scope, rails, middleware, privilege-escalation, route-confusion.</description><category>web</category><category>High</category><category>discourse</category><category>authorization-bypass</category><category>api-key-scope</category><category>rails</category><category>middleware</category><category>privilege-escalation</category><category>route-confusion</category></item></channel></rss>