PoC Archive PoC Archive

tag

WordPress

WordPress Divi Ajax Filter LFI (CVE-2026-11613)
CVE-2026-11613 web Unverified
CVE-2026-11613webCRITICAL 9.8Unverified2026-09-05WP Cookie Notice Unauthenticated File Upload RCE (CVE-2026-82970)
CVE-2026-82970 web Unverified
CVE-2026-82970webCRITICAL 10Unverified2026-09-03WordPress — Pre-Auth XSS to RCE Chain via Login Page Parser Differential (CVE-2026-64638, "XSS2Shell") EPSS 31%
CVE-2026-64638 web Unverified
CVE-2026-64638webHIGH 8.9Unverified2026-08-09wp2shell — WordPress Core Pre-Auth SQLi → Row Forgery → Admin Creation → RCE (CVE-2026-63030 + CVE-2026-60137) KEV EPSS 97%
CVE-2026-63030 (REST /batch/v1 route confusion, CVSS 7.5), CVE-2026-60137 (author__not_in SQL injection, CVSS 9.1); GHSA-ff9f-jf42-662q, GHSA-fpp7-x2x2-2mjf web Patched
CVE-2026-63030webCRITICAL 9.1Patched2026-07-19WP移行専用プラグイン for CPI <= 1.0.2 - Unauthenticated Arbitrary File Upload RCE (CVE-2025-11170)
CVE-2025-11170 web Unpatched
CVE-2025-11170webCRITICAL 9.8Unpatched2026-07-06WP Directory Kit Auto-Login Authentication Bypass to Full Site Takeover (CVE-2025-13390)
CVE-2025-13390 web Patched
CVE-2025-13390webCRITICAL 10Patched2026-07-06WordPress WPAMS Plugin Arbitrary File Upload to RCE (CVE-2025-39401)
CVE-2025-39401 web Unverified
CVE-2025-39401webCRITICAL 10Unverified2026-07-06WordPress Simple Link Directory Unauthenticated Password Reset to Admin Takeover (CVE-2025-49901)
CVE-2025-49901 web Patched
CVE-2025-49901webCRITICAL 9.8Patched2026-07-06WordPress Service Finder Bookings ≤ 6.0 Authentication Bypass via `original_user_id` Cookie (CVE-2025-5947)
CVE-2025-5947 web Unverified
CVE-2025-5947webCRITICAL 9.8Unverified2026-07-06WordPress Mobile Builder Plugin JWT Authentication Bypass to Admin Account Creation (CVE-2025-68860)
CVE-2025-68860 web Unpatched
CVE-2025-68860webCRITICAL 9.8Unpatched2026-07-06WooCommerce Dynamic Pricing & Discounts (WC Designer Pro) Unauthenticated File Upload RCE (CVE-2025-6440) EPSS 31%
CVE-2025-6440 web Unverified
CVE-2025-6440webCRITICAL 9.8Unverified2026-07-06Webkul Medical Prescription Attachment for WooCommerce — Unrestricted File Upload to Web Shell (CVE-2025-29009)
CVE-2025-29009 web Patched
CVE-2025-29009webCRITICAL 10Patched2026-07-06WavePlayer Unauthenticated Arbitrary File Upload to RCE (CVE-2025-12057)
CVE-2025-12057 web Unverified
CVE-2025-12057webCRITICAL 9.8Unverified2026-07-06TNC Toolbox: Web Performance Unauthenticated cPanel Credential Exposure (CVE-2025-12539)
CVE-2025-12539 web Patched
CVE-2025-12539webCRITICAL 10Patched2026-07-06StoryChief WordPress Plugin Unauthenticated Arbitrary File Upload via Webhook (CVE-2025-7441) EPSS 39%
CVE-2025-7441 web Unpatched
CVE-2025-7441webCRITICAL 9.8Unpatched2026-07-06StoreKeeper for WooCommerce Unauthenticated Arbitrary File Upload (CVE-2025-48148) EPSS 15%
CVE-2025-48148 web Unverified
CVE-2025-48148webCRITICAL 9.8Unverified2026-07-06Sneeit Framework <= 8.3 Unauthenticated RCE via `call_user_func()` — Rogue Admin Creation (CVE-2025-6389) EPSS 76%
CVE-2025-6389 web Unverified
CVE-2025-6389webCRITICAL 9.8Unverified2026-07-06Simple User Registration WordPress Plugin — Unauthenticated Privilege Escalation (CVE-2025-4334)
CVE-2025-4334 web Unverified
CVE-2025-4334webCRITICAL 9.8Unverified2026-07-06Simple Business Directory Pro Unauthenticated Password Reset to Admin Takeover (CVE-2025-53580)
CVE-2025-53580 web Patched
CVE-2025-53580webCRITICAL 9.8Patched2026-07-06RestroPress WordPress Plugin Unauthenticated Information Exposure Leading to JWT Forgery / Account Takeover (CVE-2025-9209)
CVE-2025-9209 web Unpatched
CVE-2025-9209webCRITICAL 9.8Unpatched2026-07-06Real Spaces WordPress Theme Unauthenticated Privilege Escalation via `imic_agent_register` (CVE-2025-6758)
CVE-2025-6758 web Unverified
CVE-2025-6758webCRITICAL 9.8Unverified2026-07-06PPOM for WooCommerce <= 33.0.15 - Unauthenticated Time-Based Blind SQL Injection (CVE-2025-11391)
CVE-2025-11391 web Patched
CVE-2025-11391webCRITICAL 9.8Patched2026-07-06Podlove Podcast Publisher <= 4.2.6 - Unauthenticated Arbitrary File Upload RCE (CVE-2025-10147)
CVE-2025-10147 web Unverified
CVE-2025-10147webCRITICAL 9.8Unverified2026-07-06Opal Estate Pro WordPress Plugin Unauthenticated Administrator Registration (CVE-2025-6934) EPSS 25%
CVE-2025-6934 web Unverified
CVE-2025-6934webCRITICAL 9.8Unverified2026-07-06Kubio AI Page Builder <= 2.5.1 Unauthenticated Local File Inclusion (CVE-2025-2294) EPSS 78%
CVE-2025-2294 web Unverified
CVE-2025-2294webCRITICAL 9.8Unverified2026-07-06KiotViet Sync Unauthenticated Arbitrary File Upload (CVE-2025-12674)
CVE-2025-12674 web Unverified
CVE-2025-12674webCRITICAL 9.8Unverified2026-07-06JAY Login & Register "Switch Back" Cookie Authentication Bypass (CVE-2025-14440)
CVE-2025-14440 web Unverified
CVE-2025-14440webCRITICAL 9.8Unverified2026-07-06GiveWP Unauthenticated PHP Object Injection via Weak Serialized-Data Regex Check (CVE-2025-22777)
CVE-2025-22777 web Patched
CVE-2025-22777webCRITICAL 9.8Patched2026-07-06Frontend Admin by DynamiApps — Unauthenticated Administrator Account Creation (CVE-2025-13342)
CVE-2025-13342 web Patched
CVE-2025-13342webCRITICAL 9.8Patched2026-07-06Fox LMS `createOrder` Unauthenticated Privilege Escalation to Administrator (CVE-2025-14156)
CVE-2025-14156 web Unverified
CVE-2025-14156webCRITICAL 9.8Unverified2026-07-06Flozen WordPress Theme Unauthenticated Arbitrary File Upload (CVE-2025-49071)
CVE-2025-49071 web Unverified
CVE-2025-49071webCRITICAL 9.8Unverified2026-07-06Cibeles AI `actualizador_git.php` Unauthenticated Arbitrary File Upload / RCE (CVE-2025-13595)
CVE-2025-13595 web Unverified
CVE-2025-13595webCRITICAL 9.8Unverified2026-07-06AI Feeds `actualizador_git.php` Unauthenticated Arbitrary File Upload / RCE (CVE-2025-13597)
CVE-2025-13597 web Unverified
CVE-2025-13597webCRITICAL 9.8Unverified2026-07-06AI Engine WordPress Plugin Unauthenticated MCP Token Disclosure to Admin Account Creation (CVE-2025-11749) EPSS 75%
CVE-2025-11749 web Unverified
CVE-2025-11749webCRITICAL 9.8Unverified2026-07-06ACF Extended (ACFE) `prepare_form()` Unauthenticated RCE via Privilege Escalation (CVE-2025-13486) EPSS 68%
CVE-2025-13486 web Unverified
CVE-2025-13486webCRITICAL 9.8Unverified2026-07-06YayMail WooCommerce Plugin Missing Authorization to Privilege Escalation — CVE-2026-1937
CVE-2026-1937 web Unverified
CVE-2026-1937webHIGH 7.2Unverified2026-07-05WPvivid Backup & Migration Unauthenticated Arbitrary File Upload RCE (CVE-2026-1357) EPSS 33%
CVE-2026-1357 web Unverified
CVE-2026-1357webCRITICALUnverified2026-07-05WP Zendesk for Contact Form 7 Unauthenticated PHP Object Injection (CVE-2026-49105)
CVE-2026-49105 web Unverified
CVE-2026-49105webHIGH 8.1Unverified2026-07-05WP Time Slots Booking Form Unauthenticated Stored XSS (CVE-2026-40791)
CVE-2026-40791 web Patched
CVE-2026-40791webHIGH 7.2Patched2026-07-05WP Photo Album Plus Unauthenticated SQL Injection — CVE-2026-6379
CVE-2026-6379 web Patched
CVE-2026-6379webCRITICAL 8.6Patched2026-07-05WP Insightly Contact Form Plugin Unauthenticated PHP Object Injection (CVE-2026-49085)
CVE-2026-49085 web Unverified
CVE-2026-49085webHIGH 8.1Unverified2026-07-05WP Captcha PRO Subscriber-to-Administrator Authentication Bypass — CVE-2026-5415
CVE-2026-5415 web Unverified
CVE-2026-5415webHIGH 8.8Unverified2026-07-05WP Activity Log Unauthenticated PHP Object Injection — CVE-2026-54806
CVE-2026-54806 web Patched
CVE-2026-54806webCRITICAL 9.8Patched2026-07-05WordPress User Language Switch Plugin SSRF — CVE-2026-0745
CVE-2026-0745 (GHSA-m38c-5p3m-p7gm) web Unverified
CVE-2026-0745webMEDIUMUnverified2026-07-05WordPress SignUp/SignIn & Invoice Generator Password-Reset Account Takeover (CVE-2026-12416 / CVE-2026-12417)
CVE-2026-12416, CVE-2026-12417 web Unverified
CVE-2026-12416, CVE-2026-12417webCRITICAL 9.8Unverified2026-07-05WordPress Ninja Forms Plugin Unauthenticated File Upload — CVE-2026-0740 EPSS 63%
CVE-2026-0740 web Unverified
CVE-2026-0740webHIGHUnverified2026-07-05WordPress HT Mega (Absolute Addons for Elementor) Unauthenticated PII Disclosure (CVE-2026-4106)
CVE-2026-4106 web Unverified
CVE-2026-4106webHIGHUnverified2026-07-05WordPress Download Manager 3.3.5.2 — Unauthenticated IDOR (CVE-2026-39676)
CVE-2026-39676 web Unverified
CVE-2026-39676webMEDIUMUnverified2026-07-05WordPress Contest Gallery Plugin Unauthenticated Blind SQL Injection — CVE-2026-3180
CVE-2026-3180 web Unverified
CVE-2026-3180webHIGHUnverified2026-07-05WordPress Breeze Cache Plugin — Unauthenticated Arbitrary File Upload (CVE-2026-3844) EPSS 28%
CVE-2026-3844 web Unverified
CVE-2026-3844webCRITICALUnverified2026-07-05WordPress "List Site Contributors" Plugin Reflected XSS Scanner (CVE-2026-0594)
CVE-2026-0594 web Unverified
CVE-2026-0594webMEDIUMUnverified2026-07-05WordPress "Import and Export Users and Customers" Plugin Privilege Escalation (CVE-2026-3629)
CVE-2026-3629 web Unverified
CVE-2026-3629webCRITICALUnverified2026-07-05WordPress "Form Maker" Plugin Unauthenticated SQL Injection — CVE-2026-3359
CVE-2026-3359 web Unverified
CVE-2026-3359webCRITICALUnverified2026-07-05WordPress "Drag and Drop File Upload for Contact Form 7" Unauthenticated RCE — CVE-2026-5364
CVE-2026-5364 web Unverified
CVE-2026-5364webHIGH 8.1Unverified2026-07-05WooCommerce Wholesale Lead Capture — Unauthenticated Privilege Escalation & File Upload RCE (CVE-2026-27542 / CVE-2026-27540)
CVE-2026-27542 (bundled with CVE-2026-27540) web Unverified
CVE-2026-27542webCRITICAL 9.8Unverified2026-07-05WooCommerce Frontend Registration Form Unauthenticated Admin Role Assignment — CVE-2026-54807
CVE-2026-54807 web Unverified
CVE-2026-54807webINFOUnverified2026-07-05WebStack WordPress Theme Unauthenticated Arbitrary File Upload RCE — CVE-2026-1555
CVE-2026-1555 web Unverified
CVE-2026-1555webCRITICAL 9.8Unverified2026-07-05User Registration Advanced Fields WordPress Plugin Unauthenticated Arbitrary File Upload (CVE-2026-4882)
CVE-2026-4882 web Unverified
CVE-2026-4882webCRITICAL 9.8Unverified2026-07-05User Registration & Membership Unauthenticated Admin Privilege Escalation (CVE-2026-1492) EPSS 24%
CVE-2026-1492 web Unverified
CVE-2026-1492webCRITICAL 9.8Unverified2026-07-05User Registration & Membership for WordPress — Unauthenticated Admin Approval Bypass (CVE-2026-6145)
CVE-2026-6145 web Unverified
CVE-2026-6145webMEDIUM 5.3Unverified2026-07-05UpdraftPlus WordPress Plugin — Unauthenticated RPC Key Bypass to Admin Creation & RCE (CVE-2026-10795)
CVE-2026-10795 web Unverified
CVE-2026-10795webCRITICALUnverified2026-07-05The Events Calendar WordPress Plugin Unauthenticated Blind SQL Injection (CVE-2026-49772)
CVE-2026-49772 web Patched
CVE-2026-49772webCRITICAL 9.3Patched2026-07-05Spectra Gutenberg Blocks Authenticated Remote Code Execution — CVE-2026-7465
CVE-2026-7465 web Unverified
CVE-2026-7465webCRITICAL 8.8Unverified2026-07-05Snow Monkey Forms — Unauthenticated Arbitrary File Deletion via Path Traversal (CVE-2026-1056) EPSS 12%
CVE-2026-1056 web Unverified
CVE-2026-1056webCRITICALUnverified2026-07-05Simple History Missing Authorization Account Takeover — CVE-2026-7459
CVE-2026-7459 web Unverified
CVE-2026-7459webHIGH 7.5Unverified2026-07-05Simple File List Plugin Unauthenticated File Modification / Path Traversal — CVE-2026-11912
CVE-2026-11912 web Patched
CVE-2026-11912webHIGH 7.5Patched2026-07-05Schema & Structured Data for WP & AMP Unauthenticated Unrestricted File Upload (CVE-2026-9067)
CVE-2026-9067 web Unverified
CVE-2026-9067webHIGH 8.1Unverified2026-07-05Prodigy Commerce WordPress Plugin — Unauthenticated Local File Inclusion (CVE-2026-0926)
CVE-2026-0926 web Unverified
CVE-2026-0926webHIGHUnverified2026-07-05Piotnet Addons for Elementor Pro Unauthenticated Arbitrary File Upload RCE (CVE-2026-4885)
CVE-2026-4885 web Unverified
CVE-2026-4885webCRITICALUnverified2026-07-05Perfmatters WordPress Plugin Arbitrary File Deletion (CVE-2026-4350)
CVE-2026-4350 web Unverified
CVE-2026-4350webHIGH 8.1Unverified2026-07-05NextScripts Social Networks Auto-Poster — WordPress Stored XSS (CVE-2026-3228)
CVE-2026-3228 web Unverified
CVE-2026-3228webMEDIUM 6.4Unverified2026-07-05midi-Synth WordPress Plugin Arbitrary File Upload (CVE-2026-1306)
CVE-2026-1306 web Unverified
CVE-2026-1306webCRITICAL 9.8Unverified2026-07-05Masteriyo LMS Authenticated Privilege Escalation to Administrator (CVE-2026-4484)
CVE-2026-4484 web Unverified
CVE-2026-4484webHIGH 8.8Unverified2026-07-05LatePoint Calendar Booking Plugin Contributor-to-Administrator Privilege Escalation (CVE-2026-49083)
CVE-2026-49083 web Unverified
CVE-2026-49083webHIGH 8.8Unverified2026-07-05LatePoint Calendar Booking Plugin Agent-to-Administrator Privilege Escalation — CVE-2026-6741
CVE-2026-6741 web Patched
CVE-2026-6741webHIGH 8.8Patched2026-07-05LA-Studio Element Kit for Elementor — Unauthenticated Admin Account Creation (CVE-2026-0920)
CVE-2026-0920 web Unverified
CVE-2026-0920webCRITICAL 9.8Unverified2026-07-05Kirki WordPress Plugin Password-Reset Hijack Leading to Account Takeover (CVE-2026-8206)
CVE-2026-8206 web Unverified
CVE-2026-8206webCRITICAL 9.8Unverified2026-07-05JetSearch WordPress Plugin Unauthenticated SQL Injection (CVE-2026-49079)
CVE-2026-49079 web Unverified
CVE-2026-49079webHIGH 7.5Unverified2026-07-05Integration for Keap/Infusionsoft Contact Form Plugin Unauthenticated PHP Object Injection (CVE-2026-49104)
CVE-2026-49104 web Unverified
CVE-2026-49104webHIGH 8.1Unverified2026-07-05Integration for ActiveCampaign Unauthenticated PHP Object Injection via Unsafe Deserialization (CVE-2026-9691)
CVE-2026-9691 web Unpatched
CVE-2026-9691webHIGH 8.1Unpatched2026-07-05Hustle (WordPress Popup) Authenticated Arbitrary File Upload via Module Import (CVE-2026-0911)
CVE-2026-0911 web Unverified
CVE-2026-0911webHIGHUnverified2026-07-05Hippoo Mobile App for WooCommerce — Unauthenticated Admin Account Takeover (CVE-2026-10580)
CVE-2026-10580 web Unverified
CVE-2026-10580webCRITICAL 9.8Unverified2026-07-05Gravity Forms Unauthenticated Reflected XSS via `gform_get_config` `form_ids` Parameter (CVE-2026-4406)
CVE-2026-4406 web Patched
CVE-2026-4406webMEDIUM 6.1Patched2026-07-05Gravity Forms Path Traversal → Arbitrary File Deletion (CVE-2026-48866)
CVE-2026-48866 web Patched
CVE-2026-48866webCRITICAL 9.6Patched2026-07-05Friendly Functions for Welcart WordPress Plugin CSRF (CVE-2026-1208)
CVE-2026-1208 web Patched
CVE-2026-1208webMEDIUM 4.3Patched2026-07-05Form Notify WordPress Plugin — LINE OAuth Authentication Bypass to Account Takeover (CVE-2026-5229)
CVE-2026-5229 web Patched
CVE-2026-5229webCRITICAL 9.8Patched2026-07-05Everest Forms Unauthenticated PHP Object Injection to RCE (CVE-2026-3296)
CVE-2026-3296 web Patched
CVE-2026-3296webCRITICAL 9.8Patched2026-07-05Everest Forms Pro Unauthenticated PHP Code Injection via Calculation Addon (CVE-2026-3300) EPSS 39%
CVE-2026-3300 web Unverified
CVE-2026-3300webCRITICALUnverified2026-07-05EventPrime WordPress Plugin Unauthenticated Arbitrary File Upload — CVE-2026-1657
CVE-2026-1657 web Patched
CVE-2026-1657webMEDIUMPatched2026-07-05Eventin (wp-event-solution) Broken Access Control / IDOR (CVE-2026-40776)
CVE-2026-40776 / Patchstack PSID 85de025d71e7 web Patched
CVE-2026-40776 / Patchstack PSID 85de025d71e7webHIGH 7.5Patched2026-07-05ElementsKit Elementor Addons Authenticated Stored XSS via REST API (CVE-2026-2600)
CVE-2026-2600 web Patched
CVE-2026-2600webMEDIUM 6.4Patched2026-07-05Easy Elements for Elementor Unauthenticated Privilege Escalation via `custom_meta` Overwrite (CVE-2026-9018)
CVE-2026-9018 web Patched
CVE-2026-9018webHIGH 8.8Patched2026-07-05Divi Form Builder <= 5.1.2 Unauthenticated Privilege Escalation via Role Injection (CVE-2026-5118)
CVE-2026-5118 web Unverified
CVE-2026-5118webCRITICAL 9.8Unverified2026-07-05Contact Form by Supsystic <= 1.7.36 Unauthenticated SSTI to RCE (CVE-2026-4257) EPSS 41%
CVE-2026-4257 web Unverified
CVE-2026-4257webCRITICALUnverified2026-07-05Business Directory Plugin for WordPress — Unauthenticated Time-Based Blind SQL Injection (CVE-2026-2576)
CVE-2026-2576 web Patched
CVE-2026-2576webHIGH 7.5Patched2026-07-05Burst Statistics WordPress Plugin Authentication Bypass to Admin Account Takeover (CVE-2026-8181) EPSS 15%
CVE-2026-8181 web Patched
CVE-2026-8181webCRITICAL 9.8Patched2026-07-05Branda White Label & Branding Plugin Unauthenticated Account Takeover — CVE-2026-11551
CVE-2026-11551 web Patched
CVE-2026-11551webCRITICAL 9.8Patched2026-07-05Bookly Booking Form Cookie-Based Stored XSS — CVE-2026-5513
CVE-2026-5513 web Patched
CVE-2026-5513webHIGH 7.2Patched2026-07-05BookingPress Pro Unauthenticated Arbitrary File Upload via Data URI Signature Field (CVE-2026-6960)
CVE-2026-6960 web Unverified
CVE-2026-6960webCRITICAL 9.8Unverified2026-07-05BetterDocs Pro Unauthenticated Local File Inclusion to RCE — CVE-2026-7515
CVE-2026-7515 web Unverified
CVE-2026-7515webCRITICAL 9.8Unverified2026-07-05Avada Builder Unauthenticated RCE via call_user_func() Allowlist Bypass (CVE-2026-6279)
CVE-2026-6279 web Unverified
CVE-2026-6279webCRITICALUnverified2026-07-05ARMember WordPress Plugin Insecure Password Reset via Plaintext Key + SQLi Chain (CVE-2026-5076)
CVE-2026-5076 (chained with CVE-2026-5073, CVE-2026-5074) web Patched
CVE-2026-5076webCRITICAL 9.8Patched2026-07-05Advanced Custom Fields: Extended Unauthenticated Privilege Escalation via `_acf_post_id` Validation Bypass (CVE-2026-8809)
CVE-2026-8809 web Unverified
CVE-2026-8809webCRITICAL 9.8Unverified2026-07-05AdForest WordPress Theme OTP Login Authentication Bypass — CVE-2026-1729
CVE-2026-1729 web Unverified
CVE-2026-1729webCRITICALUnverified2026-07-05