
CVE-2026-18366
Unauthenticated privilege-escalation PoC for WordPress Events Manager < 7.4.1; discovers colliding post/user IDs and escalates targets to…

Unauthenticated privilege-escalation PoC for WordPress Events Manager < 7.4.1; discovers colliding post/user IDs and escalates targets to…

Exploit PoC for WordPress Burst Statistics authentication bypass allowing unauthenticated admin impersonation via crafted Authorization header.

Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

Exploit PoC for unauthenticated doctor/receptionist account creation in the KiviCare WordPress plugin via improper privilege management, providing…

CVE-2026-11961 — UserRegistration: WordPress User Registration <= 5.2.2 Privilege Escalation. Misconfigured Membership Roles → Unauthenticated Admin…

PoC & checker for CVE-2026-15964 - unauthenticated password change in the WordPress plugin Single Sign On For TNG <= 2.0.0 (CVSS 9.8)

CVE-2026-13152: Custom Fields Account Registration For WooCommerce Unauthenticated Privilege Escalation PoC & Advisory by Huynh Kien Minh (MinhHK).

Hands-on exploit lab for CVE-2024-28000 — unauthenticated privilege escalation in LiteSpeed Cache (WordPress plugin, <=6.3.0.1). Spins up a…

Mirrored from tegal1337/CVE-2022-0441

Root-cause analysis, PoC, and detection guidance for CVE-2026-23550, a critical unauthenticated admin session takeover in the WordPress plugin…

Proof-of-concept exploit for CVE-2026-11551, an unauthenticated privilege escalation vulnerability in the Branda White Label plugin for WordPress,…

CVE-2026-11551: Branda Plugin - Unauthenticated Privilege Escalation via Account Takeover

PoC de CVE-2026-54420: explotacion via symlink en el plugin LiteSpeed de cPanel/WHM.

Python exploit for CVE-2026-49083, a privilege escalation vulnerability in the LatePoint Calendar Booking WordPress plugin, enabling unauthorized…

Docker-based lab for reproducing CVE-2026-49060, an unauthenticated privilege escalation in the Hippoo Mobile App for WooCommerce WordPress plugin.…

Python exploit for CVE-2026-49083 targeting privilege escalation in the LatePoint Calendar Booking WordPress plugin. Provides automated exploitation…

Defensive remediation and auditing toolkit for CVE-2026-54420 in LiteSpeed cPanel Plugin. Automates patching, detects suspicious symlinks, hunts…

Proof-of-concept exploit for CVE-2026-8181, an authentication bypass in the Burst Statistics WordPress plugin. Demonstrates remote, unauthenticated…