
CVE-2026-8809
Advanced Custom Fields: Extended <= 0.9.2.5 - Unauthenticated Privilege Escalation via Validation Bypass to '_acf_post_id' Parameter

Advanced Custom Fields: Extended <= 0.9.2.5 - Unauthenticated Privilege Escalation via Validation Bypass to '_acf_post_id' Parameter
Microsoft SQL Server sp_replwritetovarbin Memory Corruption via SQL Injection

Weaponized web shell

This exploit is based on CVE-2023-6553 and was built upon the original exploit by Chocapik, it was added that a direct reverse shell can be obtained.

POC for CVE-2025-13486

Proof-of-concept demonstrating SSRF and LFI in Metabase versions < 0.40.5 (CVE-2021-41277), including internal network scanning and access to cloud…

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the…

Advanced Custom Fields Extended (ACFE) WordPress Plugin Exploit RCE - Admin Creation

The Ultimate WordPress Toolkit – WP Extended <= 3.0.12 - Unauthenticated SQL Injection via Login Attempts Module