
CVE-2024-52380-Exploit
Picsmize plugin for WordPress is vulnerable to arbitrary file uploads.

Picsmize plugin for WordPress is vulnerable to arbitrary file uploads.

WordPress iSpring Embedder plugin <= 1.0 - CSRF to Arbitrary File Upload vulnerability

CVE-2026-5718: Unauthenticated File Upload To RCE in DnD Upload CF7 Plugin

WordPress Exclusive Content Password Protect plugin <= 1.1.0 - CSRF to Arbitrary File Upload vulnerability

Proof-of-concept exploit for CVE-2025-8889: arbitrary file upload to RCE in WordPress Compress Then Upload plugin 1.0.3. Includes step-by-step PoC…

The plugin does not prevent unauthenticated attackers from overwriting local variables when rendering templates over the REST API, which may lead to…

Cross Site Scripting vulnerability in flatpress CMS Flatpress v1.3 allows a remote attacker to execute arbitrary code via a craftedpayload to the…

Hotfix for file deletion to to code execution vulnerability in WordPress

Proof-of-concept exploit for CVE-2024-56278, a remote code execution vulnerability in the WP Ultimate Exporter WordPress plugin, demonstrating file…

Public disclosure and writeup of CVE-2021-44593, an unauthenticated SQL injection in Simple College Website leading to arbitrary file upload and…

Pre-auth path traversal to arbitrary file delete in Avada (Fusion) Builder <= 3.15.3 leading to RCE (CVSS 9.1)

Technical analysis and advisory for CVE-2026-48908: Unauthenticated Arbitrary File Upload to RCE in JoomShaper SP Page Builder.

Proof-of-Concept for CVE-2025-33053 Exploiting WebDAV with .url file delivery to demonstrate realistic remote code execution. Includes a decoy PDF…

Missing Authorization to Unauthenticated File Modification

Instant Appointment <= 1.2 — Unauthenticated Arbitrary File Upload to RCE via add_service_front AJAX | CVSS 9.8

An authenticated Stored Cross-site Scripting (XSS) vulnerability in laravel-file-manager v3.3.1 and below allows attackers with access to the file…

An authenticated Directory Traversal vulnerability in laravel-file-manager v3.3.1 and below allows attackers with access to the file manager…

WordPress FEUP Arbitrary File Upload Exploit (CVE-2025-2005)