<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WordPress — PoC Archive</title><link>https://poc.intelseclab.com/tags/wordpress/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 05 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/wordpress/index.xml" rel="self" type="application/rss+xml"/><item><title>WordPress Divi Ajax Filter LFI (CVE-2026-11613)</title><link>https://poc.intelseclab.com/pocs/web/2026-09-05_cve-2026-11613-divi-ajax-filter-lfi/</link><pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-09-05_cve-2026-11613-divi-ajax-filter-lfi/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-11613. Status: PoC. Affects: Divi Ajax Filter plugin for WordPress. Tags: LFI, WordPress, Divi, unauthenticated, Python.</description><category>web</category><category>Critical</category><category>LFI</category><category>WordPress</category><category>Divi</category><category>unauthenticated</category><category>Python</category></item><item><title>WP Cookie Notice Unauthenticated File Upload RCE (CVE-2026-82970)</title><link>https://poc.intelseclab.com/pocs/web/2026-09-03_cve-2026-82970-wplp-cookie-consent-rce/</link><pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-09-03_cve-2026-82970-wplp-cookie-consent-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-82970. Status: Weaponized. Affects: WP Cookie Notice for GDPR, CCPA &amp; ePrivacy Consent (WordPress plugin). Tags: RCE, WordPress, file upload, unauthenticated, PHP, webshell.</description><category>web</category><category>Critical</category><category>RCE</category><category>WordPress</category><category>file upload</category><category>unauthenticated</category><category>PHP</category><category>webshell</category></item><item><title>WordPress — Pre-Auth XSS to RCE Chain via Login Page Parser Differential (CVE-2026-64638, "XSS2Shell")</title><link>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-64638-wordpress-xss2shell-pre-auth-xss-to-rce/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-08-09_cve-2026-64638-wordpress-xss2shell-pre-auth-xss-to-rce/</guid><description>High severity (CVSS 8.9) — web · CVE-2026-64638. Status: Patched. Affects: WordPress Core, wp-login.php failed-login error message, KSES sanitizer vs PHP strip_tags(). Tags: wordpress, wordpress-core, pre-auth, xss, reflected-xss, xss2shell, rce, parser-differential, dom-clobbering, some, jsonp, rest-api, application-password, plugin-upload, CWE-79, CWE-94, cms.</description><category>web</category><category>High</category><category>wordpress</category><category>wordpress-core</category><category>pre-auth</category><category>xss</category><category>reflected-xss</category><category>xss2shell</category><category>rce</category><category>parser-differential</category><category>dom-clobbering</category><category>some</category><category>jsonp</category><category>rest-api</category><category>application-password</category><category>plugin-upload</category><category>CWE-79</category><category>CWE-94</category><category>cms</category></item><item><title>wp2shell — WordPress Core Pre-Auth SQLi → Row Forgery → Admin Creation → RCE (CVE-2026-63030 + CVE-2026-60137)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-63030-cve-2026-60137-wp2shell-wordpress-core-preauth-rce/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-19_cve-2026-63030-cve-2026-60137-wp2shell-wordpress-core-preauth-rce/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2026-63030 (REST /batch/v1 route confusion, CVSS 7.5), CVE-2026-60137 (author__not_in SQL injection, CVSS 9.1); GHSA-ff9f-jf42-662q, GHSA-fpp7-x2x2-2mjf. Status: Weaponized — full pre-auth RCE confirmed against stock-default WordPress core, no plugins/misconfiguration required. Affects: WordPress core (REST API /batch/v1, WP_Query::author__not_in). Tags: wordpress, wp-core, sql-injection, route-confusion, cwe-89, cwe-436, unauthenticated, remote, privilege-escalation, rce, oembed, changeset.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wp-core</category><category>sql-injection</category><category>route-confusion</category><category>cwe-89</category><category>cwe-436</category><category>unauthenticated</category><category>remote</category><category>privilege-escalation</category><category>rce</category><category>oembed</category><category>changeset</category></item><item><title>WP移行専用プラグイン for CPI &lt;= 1.0.2 - Unauthenticated Arbitrary File Upload RCE (CVE-2025-11170)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-11170-cpi-plugin-file-upload-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-11170-cpi-plugin-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-11170. Status: Weaponized. Affects: WP移行専用プラグイン for CPI (cpi-wp-migration, a CPI/site-migration import plugin for WordPress). Tags: wordpress, cpi-wp-migration, unauthenticated-file-upload, rce, admin-ajax, cwe-434, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>cpi-wp-migration</category><category>unauthenticated-file-upload</category><category>rce</category><category>admin-ajax</category><category>cwe-434</category><category>python</category></item><item><title>WP Directory Kit Auto-Login Authentication Bypass to Full Site Takeover (CVE-2025-13390)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13390-wp-directory-kit-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13390-wp-directory-kit-auth-bypass/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-13390. Status: Weaponized. Affects: WP Directory Kit (WordPress plugin). Tags: wordpress, wp-directory-kit, authentication-bypass, predictable-token, account-takeover, webshell-upload, python, cwe-287.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wp-directory-kit</category><category>authentication-bypass</category><category>predictable-token</category><category>account-takeover</category><category>webshell-upload</category><category>python</category><category>cwe-287</category></item><item><title>WordPress WPAMS Plugin Arbitrary File Upload to RCE (CVE-2025-39401)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-39401-wpams-arbitrary-file-upload-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-39401-wpams-arbitrary-file-upload-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-39401. Status: Weaponized. Affects: WPAMS (WordPress Apartment/Property Management System) plugin by mojoomla. Tags: wordpress, wpams, mojoomla, arbitrary-file-upload, webshell, rce, unauthenticated, python, multithreaded, cwe-434.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wpams</category><category>mojoomla</category><category>arbitrary-file-upload</category><category>webshell</category><category>rce</category><category>unauthenticated</category><category>python</category><category>multithreaded</category><category>cwe-434</category></item><item><title>WordPress Simple Link Directory Unauthenticated Password Reset to Admin Takeover (CVE-2025-49901)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-49901-simple-link-directory-password-reset-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-49901-simple-link-directory-password-reset-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-49901. Status: Weaponized. Affects: WordPress "Simple Link Directory" plugin (qc-simple-link-directory by quantumcloud). Tags: wordpress, wordpress-plugin, simple-link-directory, qc-opd, authentication-bypass, password-reset, broken-authentication, cwe-288, username-enumeration, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wordpress-plugin</category><category>simple-link-directory</category><category>qc-opd</category><category>authentication-bypass</category><category>password-reset</category><category>broken-authentication</category><category>cwe-288</category><category>username-enumeration</category><category>python</category></item><item><title>WordPress Service Finder Bookings ≤ 6.0 Authentication Bypass via `original_user_id` Cookie (CVE-2025-5947)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-5947-servicefinder-bookings-cookie-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-5947-servicefinder-bookings-cookie-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-5947. Status: Weaponized. Affects: WordPress plugin "Service Finder Bookings" (sf-booking). Tags: wordpress, service-finder-bookings, sf-booking, authentication-bypass, cookie-forgery, privilege-escalation, cwe-639.</description><category>web</category><category>Critical</category><category>wordpress</category><category>service-finder-bookings</category><category>sf-booking</category><category>authentication-bypass</category><category>cookie-forgery</category><category>privilege-escalation</category><category>cwe-639</category></item><item><title>WordPress Mobile Builder Plugin JWT Authentication Bypass to Admin Account Creation (CVE-2025-68860)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-68860-wp-jwt-admin-forge/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-68860-wp-jwt-admin-forge/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-68860. Status: Weaponized. Affects: WordPress "Mobile Builder" plugin. Tags: wordpress, mobile-builder, jwt, authentication-bypass, hardcoded-secret, privilege-escalation, rest-api, python, cwe-288.</description><category>web</category><category>Critical</category><category>wordpress</category><category>mobile-builder</category><category>jwt</category><category>authentication-bypass</category><category>hardcoded-secret</category><category>privilege-escalation</category><category>rest-api</category><category>python</category><category>cwe-288</category></item><item><title>WooCommerce Dynamic Pricing &amp; Discounts (WC Designer Pro) Unauthenticated File Upload RCE (CVE-2025-6440)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6440-woocommerce-dynamic-pricing-file-upload-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6440-woocommerce-dynamic-pricing-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-6440. Status: Weaponized. Affects: WordPress WooCommerce Dynamic Pricing &amp; Discounts plugin (wc-designer-pro). Tags: wordpress, woocommerce, wc-designer-pro, dynamic-pricing, file-upload, rce, unauthenticated, wp-ajax, cwe-434, nuclei.</description><category>web</category><category>Critical</category><category>wordpress</category><category>woocommerce</category><category>wc-designer-pro</category><category>dynamic-pricing</category><category>file-upload</category><category>rce</category><category>unauthenticated</category><category>wp-ajax</category><category>cwe-434</category><category>nuclei</category></item><item><title>Webkul Medical Prescription Attachment for WooCommerce — Unrestricted File Upload to Web Shell (CVE-2025-29009)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-29009-woocommerce-medical-prescription-file-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-29009-woocommerce-medical-prescription-file-upload/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-29009. Status: Weaponized. Affects: Webkul "Medical Prescription Attachment Plugin for WooCommerce" (WordPress plugin). Tags: wordpress, woocommerce, medical-prescription-attachment, unrestricted-file-upload, webshell, cwe-434, unauthenticated, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>woocommerce</category><category>medical-prescription-attachment</category><category>unrestricted-file-upload</category><category>webshell</category><category>cwe-434</category><category>unauthenticated</category><category>python</category></item><item><title>WavePlayer Unauthenticated Arbitrary File Upload to RCE (CVE-2025-12057)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12057-waveplayer-webshell-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12057-waveplayer-webshell-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-12057. Status: Weaponized. Affects: WavePlayer (WordPress plugin). Tags: wordpress, waveplayer, arbitrary-file-upload, unauthenticated, rce, webshell, ajax, nonce, php, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>waveplayer</category><category>arbitrary-file-upload</category><category>unauthenticated</category><category>rce</category><category>webshell</category><category>ajax</category><category>nonce</category><category>php</category><category>python</category></item><item><title>TNC Toolbox: Web Performance Unauthenticated cPanel Credential Exposure (CVE-2025-12539)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12539-tnc-toolbox-cpanel-creds-exposure/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12539-tnc-toolbox-cpanel-creds-exposure/</guid><description>Critical severity (CVSS 10) — web · CVE-2025-12539. Status: Weaponized. Affects: TNC Toolbox: Web Performance (WordPress plugin). Tags: wordpress, tnc-toolbox, sensitive-information-exposure, unauthenticated, cpanel, credential-theft, privilege-escalation, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>tnc-toolbox</category><category>sensitive-information-exposure</category><category>unauthenticated</category><category>cpanel</category><category>credential-theft</category><category>privilege-escalation</category><category>python</category></item><item><title>StoryChief WordPress Plugin Unauthenticated Arbitrary File Upload via Webhook (CVE-2025-7441)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-7441-storychief-webhook-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-7441-storychief-webhook-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-7441. Status: PoC. Affects: StoryChief WordPress plugin. Tags: storychief, wordpress, wordpress-plugin, arbitrary-file-upload, ssrf, remote-code-execution, unauthenticated, webhook, hmac, cwe-434, python.</description><category>web</category><category>Critical</category><category>storychief</category><category>wordpress</category><category>wordpress-plugin</category><category>arbitrary-file-upload</category><category>ssrf</category><category>remote-code-execution</category><category>unauthenticated</category><category>webhook</category><category>hmac</category><category>cwe-434</category><category>python</category></item><item><title>StoreKeeper for WooCommerce Unauthenticated Arbitrary File Upload (CVE-2025-48148)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-48148-storekeeper-woocommerce-webshell-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-48148-storekeeper-woocommerce-webshell-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-48148. Status: Weaponized. Affects: StoreKeeper for WooCommerce (WordPress plugin). Tags: wordpress, woocommerce, storekeeper, arbitrary-file-upload, unauthenticated, webshell, rce, cwe-434, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>woocommerce</category><category>storekeeper</category><category>arbitrary-file-upload</category><category>unauthenticated</category><category>webshell</category><category>rce</category><category>cwe-434</category><category>python</category></item><item><title>Sneeit Framework &lt;= 8.3 Unauthenticated RCE via `call_user_func()` — Rogue Admin Creation (CVE-2025-6389)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6389-wordpress-rogue-admin-user-creation/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6389-wordpress-rogue-admin-user-creation/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-6389. Status: Weaponized. Affects: Sneeit Framework (WordPress theme framework plugin, sneeit-framework). Tags: wordpress, sneeit-framework, rce, call_user_func, unauthenticated, wp_insert_user, privilege-escalation, admin-takeover, cwe-94, wp-ajax-nopriv.</description><category>web</category><category>Critical</category><category>wordpress</category><category>sneeit-framework</category><category>rce</category><category>call_user_func</category><category>unauthenticated</category><category>wp_insert_user</category><category>privilege-escalation</category><category>admin-takeover</category><category>cwe-94</category><category>wp-ajax-nopriv</category></item><item><title>Simple User Registration WordPress Plugin — Unauthenticated Privilege Escalation (CVE-2025-4334)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-4334-simple-user-registration-privesc/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-4334-simple-user-registration-privesc/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-4334. Status: PoC. Affects: "Simple User Registration" WordPress plugin (registration/form-builder plugin, wpr_submit_form AJAX action). Tags: wordpress, wp-plugin, simple-user-registration, privilege-escalation, unauthenticated, admin-ajax, cwe-269, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wp-plugin</category><category>simple-user-registration</category><category>privilege-escalation</category><category>unauthenticated</category><category>admin-ajax</category><category>cwe-269</category><category>python</category></item><item><title>Simple Business Directory Pro Unauthenticated Password Reset to Admin Takeover (CVE-2025-53580)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-53580-sbd-password-reset-privesc/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-53580-sbd-password-reset-privesc/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-53580. Status: Weaponized. Affects: quantumcloud "Simple Business Directory Pro" WordPress plugin (simple-business-directory-pro). Tags: wordpress, wordpress-plugin, simple-business-directory-pro, password-reset, privilege-escalation, incorrect-privilege-assignment, cwe-266, account-takeover, unauthenticated, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wordpress-plugin</category><category>simple-business-directory-pro</category><category>password-reset</category><category>privilege-escalation</category><category>incorrect-privilege-assignment</category><category>cwe-266</category><category>account-takeover</category><category>unauthenticated</category><category>python</category></item><item><title>RestroPress WordPress Plugin Unauthenticated Information Exposure Leading to JWT Forgery / Account Takeover (CVE-2025-9209)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-9209-restropress-jwt-forgery/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-9209-restropress-jwt-forgery/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-9209. Status: Weaponized. Affects: RestroPress – Online Food Ordering System (WordPress plugin). Tags: restropress, wordpress, wordpress-plugin, information-exposure, jwt, authentication-bypass, account-takeover, rest-api, mass-scanner, cwe-200, cwe-287, python.</description><category>web</category><category>Critical</category><category>restropress</category><category>wordpress</category><category>wordpress-plugin</category><category>information-exposure</category><category>jwt</category><category>authentication-bypass</category><category>account-takeover</category><category>rest-api</category><category>mass-scanner</category><category>cwe-200</category><category>cwe-287</category><category>python</category></item><item><title>Real Spaces WordPress Theme Unauthenticated Privilege Escalation via `imic_agent_register` (CVE-2025-6758)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6758-realspaces-privesc/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6758-realspaces-privesc/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-6758. Status: Weaponized. Affects: Real Spaces - Properties Directory Theme for WordPress (imic_agent_register AJAX handler). Tags: wordpress, real-spaces, imic, privilege-escalation, unauthenticated, admin-ajax, role-assignment, cwe-269, cwe-863, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>real-spaces</category><category>imic</category><category>privilege-escalation</category><category>unauthenticated</category><category>admin-ajax</category><category>role-assignment</category><category>cwe-269</category><category>cwe-863</category><category>python</category></item><item><title>PPOM for WooCommerce &lt;= 33.0.15 - Unauthenticated Time-Based Blind SQL Injection (CVE-2025-11391)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-11391-ppom-woocommerce-blind-sqli/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-11391-ppom-woocommerce-blind-sqli/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-11391. Status: Patched. Affects: PPOM for WooCommerce (woocommerce-product-addon plugin). Tags: wordpress, woocommerce, ppom, product-addon, sql-injection, blind-sqli, time-based, cwe-89, python, php.</description><category>web</category><category>Critical</category><category>wordpress</category><category>woocommerce</category><category>ppom</category><category>product-addon</category><category>sql-injection</category><category>blind-sqli</category><category>time-based</category><category>cwe-89</category><category>python</category><category>php</category></item><item><title>Podlove Podcast Publisher &lt;= 4.2.6 - Unauthenticated Arbitrary File Upload RCE (CVE-2025-10147)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-10147-podlove-podcast-publisher-file-upload-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-10147-podlove-podcast-publisher-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-10147. Status: Weaponized. Affects: Podlove Podcast Publisher (WordPress plugin). Tags: wordpress, podlove, podcast-publisher, unauthenticated-file-upload, rce, cwe-434, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>podlove</category><category>podcast-publisher</category><category>unauthenticated-file-upload</category><category>rce</category><category>cwe-434</category><category>python</category></item><item><title>Opal Estate Pro WordPress Plugin Unauthenticated Administrator Registration (CVE-2025-6934)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6934-opal-estate-admin-register/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-6934-opal-estate-admin-register/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-6934. Status: Weaponized. Affects: Opal Estate Pro (WordPress real-estate plugin). Tags: wordpress, opal-estate-pro, privilege-escalation, unauthenticated-registration, admin-ajax, nonce-abuse, cwe-269, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>opal-estate-pro</category><category>privilege-escalation</category><category>unauthenticated-registration</category><category>admin-ajax</category><category>nonce-abuse</category><category>cwe-269</category><category>python</category></item><item><title>Kubio AI Page Builder &lt;= 2.5.1 Unauthenticated Local File Inclusion (CVE-2025-2294)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-2294-kubio-lfi/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-2294-kubio-lfi/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-2294. Status: PoC. Affects: Kubio AI Page Builder (WordPress plugin). Tags: wordpress, kubio, page-builder, lfi, local-file-inclusion, unauthenticated, php, python, cwe-98.</description><category>web</category><category>Critical</category><category>wordpress</category><category>kubio</category><category>page-builder</category><category>lfi</category><category>local-file-inclusion</category><category>unauthenticated</category><category>php</category><category>python</category><category>cwe-98</category></item><item><title>KiotViet Sync Unauthenticated Arbitrary File Upload (CVE-2025-12674)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12674-kiotviet-sync-file-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-12674-kiotviet-sync-file-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-12674. Status: Weaponized. Affects: KiotViet Sync (WordPress plugin). Tags: wordpress, kiotviet-sync, arbitrary-file-upload, unauthenticated, rce, rest-api, webshell, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>kiotviet-sync</category><category>arbitrary-file-upload</category><category>unauthenticated</category><category>rce</category><category>rest-api</category><category>webshell</category><category>python</category></item><item><title>JAY Login &amp; Register "Switch Back" Cookie Authentication Bypass (CVE-2025-14440)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14440-jay-login-register-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14440-jay-login-register-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-14440. Status: Weaponized. Affects: JAY Login &amp; Register (WordPress plugin). Tags: wordpress, jay-login-register, authentication-bypass, cookie-manipulation, unauthenticated, python, cwe-287, cwe-290.</description><category>web</category><category>Critical</category><category>wordpress</category><category>jay-login-register</category><category>authentication-bypass</category><category>cookie-manipulation</category><category>unauthenticated</category><category>python</category><category>cwe-287</category><category>cwe-290</category></item><item><title>GiveWP Unauthenticated PHP Object Injection via Weak Serialized-Data Regex Check (CVE-2025-22777)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-22777-givewp-php-object-injection/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-22777-givewp-php-object-injection/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-22777. Status: PoC. Affects: GiveWP – Donation Plugin and Fundraising Platform (WordPress plugin, 100,000+ active installs). Tags: givewp, wordpress, wordpress-plugin, php-object-injection, deserialization, unserialize, gadget-chain, cwe-502, php, unauthenticated.</description><category>web</category><category>Critical</category><category>givewp</category><category>wordpress</category><category>wordpress-plugin</category><category>php-object-injection</category><category>deserialization</category><category>unserialize</category><category>gadget-chain</category><category>cwe-502</category><category>php</category><category>unauthenticated</category></item><item><title>Frontend Admin by DynamiApps — Unauthenticated Administrator Account Creation (CVE-2025-13342)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13342-frontend-admin-unauth-admin-creation/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13342-frontend-admin-unauth-admin-creation/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-13342. Status: Weaponized. Affects: Frontend Admin by DynamiApps (WordPress plugin built on Advanced Custom Fields / ACF frontend forms). Tags: wordpress, wordpress-plugin, frontend-admin, dynamiapps, acf, advanced-custom-fields, broken-access-control, cwe-284, privilege-escalation, unauthenticated, admin-takeover, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wordpress-plugin</category><category>frontend-admin</category><category>dynamiapps</category><category>acf</category><category>advanced-custom-fields</category><category>broken-access-control</category><category>cwe-284</category><category>privilege-escalation</category><category>unauthenticated</category><category>admin-takeover</category><category>python</category></item><item><title>Fox LMS `createOrder` Unauthenticated Privilege Escalation to Administrator (CVE-2025-14156)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14156-fox-lms-privilege-escalation/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-14156-fox-lms-privilege-escalation/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-14156. Status: Weaponized. Affects: Fox LMS (WordPress LMS plugin). Tags: wordpress, fox-lms, rest-api, privilege-escalation, role-injection, unauthenticated, python, cwe-269.</description><category>web</category><category>Critical</category><category>wordpress</category><category>fox-lms</category><category>rest-api</category><category>privilege-escalation</category><category>role-injection</category><category>unauthenticated</category><category>python</category><category>cwe-269</category></item><item><title>Flozen WordPress Theme Unauthenticated Arbitrary File Upload (CVE-2025-49071)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-49071-flozen-theme-arbitrary-file-upload/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-49071-flozen-theme-arbitrary-file-upload/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-49071. Status: Weaponized. Affects: Flozen Theme for WordPress. Tags: wordpress, flozen-theme, arbitrary-file-upload, unauthenticated, webshell, zip-upload, rce, cwe-434, python.</description><category>web</category><category>Critical</category><category>wordpress</category><category>flozen-theme</category><category>arbitrary-file-upload</category><category>unauthenticated</category><category>webshell</category><category>zip-upload</category><category>rce</category><category>cwe-434</category><category>python</category></item><item><title>Cibeles AI `actualizador_git.php` Unauthenticated Arbitrary File Upload / RCE (CVE-2025-13595)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13595-cibeles-ai-file-upload-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13595-cibeles-ai-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-13595. Status: Weaponized. Affects: Cibeles AI (WordPress plugin). Tags: wordpress, cibeles-ai, unauthenticated-file-upload, github-mirror-abuse, webshell, python, cwe-434, cwe-306.</description><category>web</category><category>Critical</category><category>wordpress</category><category>cibeles-ai</category><category>unauthenticated-file-upload</category><category>github-mirror-abuse</category><category>webshell</category><category>python</category><category>cwe-434</category><category>cwe-306</category></item><item><title>AI Feeds `actualizador_git.php` Unauthenticated Arbitrary File Upload / RCE (CVE-2025-13597)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13597-ai-feeds-file-upload-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13597-ai-feeds-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-13597. Status: Weaponized. Affects: AI Feeds (WordPress plugin). Tags: wordpress, ai-feeds, unauthenticated-file-upload, github-mirror-abuse, webshell, python, cwe-434, cwe-306.</description><category>web</category><category>Critical</category><category>wordpress</category><category>ai-feeds</category><category>unauthenticated-file-upload</category><category>github-mirror-abuse</category><category>webshell</category><category>python</category><category>cwe-434</category><category>cwe-306</category></item><item><title>AI Engine WordPress Plugin Unauthenticated MCP Token Disclosure to Admin Account Creation (CVE-2025-11749)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-11749-ai-engine-admin-account-creation/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-11749-ai-engine-admin-account-creation/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-11749. Status: Weaponized. Affects: AI Engine plugin for WordPress (mwai). Tags: wordpress, ai-engine, mwai, mcp, rest-api, information-disclosure, privilege-escalation, admin-account-creation, python, mass-scanner.</description><category>web</category><category>Critical</category><category>wordpress</category><category>ai-engine</category><category>mwai</category><category>mcp</category><category>rest-api</category><category>information-disclosure</category><category>privilege-escalation</category><category>admin-account-creation</category><category>python</category><category>mass-scanner</category></item><item><title>ACF Extended (ACFE) `prepare_form()` Unauthenticated RCE via Privilege Escalation (CVE-2025-13486)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13486-acf-extended-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-06_cve-2025-13486-acf-extended-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2025-13486. Status: Weaponized. Affects: Advanced Custom Fields: Extended (ACFE) — WordPress plugin. Tags: wordpress, acf-extended, acfe, call_user_func_array, unauthenticated-rce, privilege-escalation, admin-account-creation, python, cwe-94.</description><category>web</category><category>Critical</category><category>wordpress</category><category>acf-extended</category><category>acfe</category><category>call_user_func_array</category><category>unauthenticated-rce</category><category>privilege-escalation</category><category>admin-account-creation</category><category>python</category><category>cwe-94</category></item><item><title>YayMail WooCommerce Plugin Missing Authorization to Privilege Escalation — CVE-2026-1937</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1937-yaymail-woocommerce-privesc/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1937-yaymail-woocommerce-privesc/</guid><description>High severity (CVSS 7.2) — web · CVE-2026-1937. Status: Weaponized. Affects: YayMail – WooCommerce Email Customizer plugin for WordPress. Tags: wordpress, woocommerce, plugin, missing-authorization, privilege-escalation, mass-exploitation, ajax.</description><category>web</category><category>High</category><category>wordpress</category><category>woocommerce</category><category>plugin</category><category>missing-authorization</category><category>privilege-escalation</category><category>mass-exploitation</category><category>ajax</category></item><item><title>WPvivid Backup &amp; Migration Unauthenticated Arbitrary File Upload RCE (CVE-2026-1357)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1357-wpvivid-file-upload-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-1357-wpvivid-file-upload-rce/</guid><description>Critical severity — web · CVE-2026-1357. Status: Weaponized. Affects: WPvivid Backup &amp; Migration WordPress plugin. Tags: wordpress, wpvivid, arbitrary-file-upload, rce, unauthenticated, cryptography, path-traversal.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wpvivid</category><category>arbitrary-file-upload</category><category>rce</category><category>unauthenticated</category><category>cryptography</category><category>path-traversal</category></item><item><title>WP Zendesk for Contact Form 7 Unauthenticated PHP Object Injection (CVE-2026-49105)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49105-wp-zendesk-cf7-php-object-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49105-wp-zendesk-cf7-php-object-injection/</guid><description>High severity (CVSS 8.1) — web · CVE-2026-49105. Status: PoC. Affects: WP Zendesk for Contact Form 7 plugin for WordPress, cf7-zendesk.php. Tags: wordpress, zendesk, php-object-injection, deserialization, contact-form-7, pop-chain, unauthenticated.</description><category>web</category><category>High</category><category>wordpress</category><category>zendesk</category><category>php-object-injection</category><category>deserialization</category><category>contact-form-7</category><category>pop-chain</category><category>unauthenticated</category></item><item><title>WP Time Slots Booking Form Unauthenticated Stored XSS (CVE-2026-40791)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40791-wp-time-slots-booking-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-40791-wp-time-slots-booking-xss/</guid><description>High severity (CVSS 7.2) — web · CVE-2026-40791. Status: PoC. Affects: WP Time Slots Booking Form (wp-time-slots-booking-form WordPress plugin). Tags: wordpress, wordpress-plugin, stored-xss, unauthenticated, cwe-79, admin-takeover, booking-form.</description><category>web</category><category>High</category><category>wordpress</category><category>wordpress-plugin</category><category>stored-xss</category><category>unauthenticated</category><category>cwe-79</category><category>admin-takeover</category><category>booking-form</category></item><item><title>WP Photo Album Plus Unauthenticated SQL Injection — CVE-2026-6379</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-6379-wp-photo-album-plus-sqli/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-6379-wp-photo-album-plus-sqli/</guid><description>Critical severity (CVSS 8.6) — web · CVE-2026-6379. Status: PoC. Affects: WordPress plugin "WP Photo Album Plus" (WPPA+) by opajaap. Tags: wordpress, wp-photo-album-plus, sql-injection, unauthenticated, time-based-blind, cwe-89.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wp-photo-album-plus</category><category>sql-injection</category><category>unauthenticated</category><category>time-based-blind</category><category>cwe-89</category></item><item><title>WP Insightly Contact Form Plugin Unauthenticated PHP Object Injection (CVE-2026-49085)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49085-wp-insightly-php-object-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49085-wp-insightly-php-object-injection/</guid><description>High severity (CVSS 8.1) — web · CVE-2026-49085. Status: PoC. Affects: WP Insightly (Contact Form 7 to Insightly CRM integration) plugin for WordPress, cf7-insightly.php. Tags: wordpress, insightly, php-object-injection, deserialization, contact-form-7, pop-chain, unauthenticated.</description><category>web</category><category>High</category><category>wordpress</category><category>insightly</category><category>php-object-injection</category><category>deserialization</category><category>contact-form-7</category><category>pop-chain</category><category>unauthenticated</category></item><item><title>WP Captcha PRO Subscriber-to-Administrator Authentication Bypass — CVE-2026-5415</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5415-wp-captcha-pro-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-5415-wp-captcha-pro-auth-bypass/</guid><description>High severity (CVSS 8.8) — web · CVE-2026-5415. Status: PoC. Affects: WP Captcha PRO (WordPress plugin, Advanced Google reCAPTCHA). Tags: wordpress, wp-captcha-pro, auth-bypass, privilege-escalation, nonce, ajax, account-takeover, plugin.</description><category>web</category><category>High</category><category>wordpress</category><category>wp-captcha-pro</category><category>auth-bypass</category><category>privilege-escalation</category><category>nonce</category><category>ajax</category><category>account-takeover</category><category>plugin</category></item><item><title>WP Activity Log Unauthenticated PHP Object Injection — CVE-2026-54806</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-54806-wp-activity-log-poi-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-54806-wp-activity-log-poi-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-54806. Status: PoC. Affects: WP Activity Log (plugin slug: wp-security-audit-log) by Melapress, for WordPress. Tags: wordpress, wp-activity-log, wp-security-audit-log, php-object-injection, deserialization, cwe-502, blind-rce, gadget-chain.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wp-activity-log</category><category>wp-security-audit-log</category><category>php-object-injection</category><category>deserialization</category><category>cwe-502</category><category>blind-rce</category><category>gadget-chain</category></item><item><title>WordPress User Language Switch Plugin SSRF — CVE-2026-0745</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0745-uls-plugin-ssrf/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0745-uls-plugin-ssrf/</guid><description>Medium severity — web · CVE-2026-0745 (GHSA-m38c-5p3m-p7gm). Status: PoC. Affects: WordPress "User Language Switch" plugin. Tags: wordpress, ssrf, plugin-vulnerability, admin-ajax, cwe-918, metadata-endpoint.</description><category>web</category><category>Medium</category><category>wordpress</category><category>ssrf</category><category>plugin-vulnerability</category><category>admin-ajax</category><category>cwe-918</category><category>metadata-endpoint</category></item><item><title>WordPress SignUp/SignIn &amp; Invoice Generator Password-Reset Account Takeover (CVE-2026-12416 / CVE-2026-12417)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-12416-wp-password-reset-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-12416-wp-password-reset-bypass/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-12416, CVE-2026-12417. Status: Weaponized. Affects: SignUp &amp; SignIn WordPress plugin (CVE-2026-12417); Invoice Generator WordPress plugin (CVE-2026-12416). Tags: wordpress, wp-plugin, account-takeover, password-reset, auth-bypass, ajax, mass-exploitation.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wp-plugin</category><category>account-takeover</category><category>password-reset</category><category>auth-bypass</category><category>ajax</category><category>mass-exploitation</category></item><item><title>WordPress Ninja Forms Plugin Unauthenticated File Upload — CVE-2026-0740</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0740-ninja-forms-file-upload/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-0740-ninja-forms-file-upload/</guid><description>High severity — web · CVE-2026-0740. Status: PoC. Affects: WordPress "Ninja Forms" plugin — file upload field/module. Tags: wordpress, ninja-forms, file-upload, webshell, admin-ajax, plugin-vulnerability, cwe-434.</description><category>web</category><category>High</category><category>wordpress</category><category>ninja-forms</category><category>file-upload</category><category>webshell</category><category>admin-ajax</category><category>plugin-vulnerability</category><category>cwe-434</category></item><item><title>WordPress HT Mega (Absolute Addons for Elementor) Unauthenticated PII Disclosure (CVE-2026-4106)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4106-htmega-wordpress-pii-disclosure/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4106-htmega-wordpress-pii-disclosure/</guid><description>High severity — web · CVE-2026-4106. Status: Weaponized. Affects: HT Mega – Absolute Addons for Elementor (WordPress plugin). Tags: wordpress, elementor, ht-mega, wp-ajax, pii-disclosure, missing-authorization, mass-scanner, plugin-vulnerability.</description><category>web</category><category>High</category><category>wordpress</category><category>elementor</category><category>ht-mega</category><category>wp-ajax</category><category>pii-disclosure</category><category>missing-authorization</category><category>mass-scanner</category><category>plugin-vulnerability</category></item><item><title>WordPress Download Manager 3.3.5.2 — Unauthenticated IDOR (CVE-2026-39676)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39676-wordpress-download-manager-idor/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39676-wordpress-download-manager-idor/</guid><description>Medium severity — web · CVE-2026-39676. Status: PoC. Affects: Download Manager plugin for WordPress. Tags: wordpress, wordpress-plugin, idor, missing-authorization, unauthenticated, download-manager.</description><category>web</category><category>Medium</category><category>wordpress</category><category>wordpress-plugin</category><category>idor</category><category>missing-authorization</category><category>unauthenticated</category><category>download-manager</category></item><item><title>WordPress Contest Gallery Plugin Unauthenticated Blind SQL Injection — CVE-2026-3180</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3180-contest-gallery-blind-sqli/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3180-contest-gallery-blind-sqli/</guid><description>High severity — web · CVE-2026-3180. Status: PoC. Affects: WordPress "Contest Gallery" plugin. Tags: wordpress, sqli, blind-sqli, plugin, admin-ajax, unauthenticated, php, boolean-based.</description><category>web</category><category>High</category><category>wordpress</category><category>sqli</category><category>blind-sqli</category><category>plugin</category><category>admin-ajax</category><category>unauthenticated</category><category>php</category><category>boolean-based</category></item><item><title>WordPress Breeze Cache Plugin — Unauthenticated Arbitrary File Upload (CVE-2026-3844)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3844-wordpress-breeze-cache-file-upload/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-3844-wordpress-breeze-cache-file-upload/</guid><description>Critical severity — web · CVE-2026-3844. Status: PoC. Affects: Breeze Cache plugin for WordPress. Tags: wordpress, wordpress-plugin, unauthenticated, file-upload, rce, gravatar-cache, breeze-cache.</description><category>web</category><category>Critical</category><category>wordpress</category><category>wordpress-plugin</category><category>unauthenticated</category><category>file-upload</category><category>rce</category><category>gravatar-cache</category><category>breeze-cache</category></item></channel></rss>