
By-Poloss..-..CVE-2026-11551-PoC
Unauthenticated Privilege Escalation via Account Takeover

Unauthenticated Privilege Escalation via Account Takeover

CVE-2020-13654 - XWiki Platform < 12.8 - Stored XSS → CSRF → Account Takeover

WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover

CVE-2026-8181 | Burst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account Takeover

Motors <= 5.6.67 - Unauthenticated Privilege Escalation via Password Update/Account Takeover

eventin <= 4.0.34 - privilege escalation via user email change / account takeover for authenticated contributor+

Flynax Bridge <= 2.2.0 - Unauthenticated Privilege Escalation via Account Takeover

Eventin <= 4.0.34 - Authenticated (Contributor+) Privilege Escalation via User Email Change/Account Takeover

CVE-2025-4322 – Unauthenticated Privilege Escalation via Password Update "Account Takeover" 🔥

Sala - Startup & SaaS WordPress Theme <= 1.1.4 - Unauthenticated Privilege Escalation via Password Reset/Account Takeover

Exploit chain for WordPress Core using REST API route-confusion and SQL injection for unauthenticated RCE, privilege escalation, and full server…

Root takeover via signature spoofing in KernelSU

CVE-2025-59501 POC code

Web CTF challenge highlighting moodle CVE-2025-26529 (in 2 flavors)

An improved POC exploit based on the reported CVE on exploitdb

WordPress Frontend Login and Registration Blocks Plugin <= 1.0.7 is vulnerable to Privilege Escalation
