
CVE-2026-8809
Advanced Custom Fields: Extended <= 0.9.2.5 - Unauthenticated Privilege Escalation via Validation Bypass to '_acf_post_id' Parameter

Advanced Custom Fields: Extended <= 0.9.2.5 - Unauthenticated Privilege Escalation via Validation Bypass to '_acf_post_id' Parameter
Microsoft SQL Server sp_replwritetovarbin Memory Corruption via SQL Injection

Weaponized web shell

This exploit is based on CVE-2023-6553 and was built upon the original exploit by Chocapik, it was added that a direct reverse shell can be obtained.

POC for CVE-2025-13486

Docker test environment for CVE-2025-13486 (ACF Extended RCE). For security research only.

Proof-of-concept demonstrating SSRF and LFI in Metabase versions < 0.40.5 (CVE-2021-41277), including internal network scanning and access to cloud…

my extended take on Mark Brand's CVE 2016-3861 libutils bug

The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 through 0.9.1.1 via the…

Vulnerable setup for CVE-2025-13486 - Advanced Custom Fields: Extended - Remote Code Execution

Advanced Custom Fields Extended (ACFE) WordPress Plugin Exploit RCE - Admin Creation

The Ultimate WordPress Toolkit – WP Extended <= 3.0.12 - Unauthenticated SQL Injection via Login Attempts Module