Proof of Concept
Community PoC archive. Use responsibly and only in authorized test environments.
CVE-2026-93399 — Bookly WordPress IDOR (Order Token Leak & Booking Rollback)
criticalBookly ≤ 28.2: unauthenticated IDOR on booking AJAX — bookly_get_form_id + bookly_render_complete leak any order’s bookly_order token; calendar export and rollback cancel non-completed bookings. CVSS 3.1 9.1 Critical (CWE-639).
@admin · 9/25/2026CVE-2026-89055 — CusRev WooCommerce Missing Authorization (Arbitrary Media Deletion)
criticalCustomer Reviews for WooCommerce (CusRev) ≤ 5.120.0: public review form AJAX accepts arbitrary Media Library attachment IDs; linked files are deleted when the review is purged. CVSS 3.1 9.1 Critical (CWE-862). Requires a /cusrev/{formId}/ link.
@admin · 9/25/2026CVE-2026-14281 — WAWP WordPress Unauthenticated Privilege Escalation (≤ 4.8.6)
criticalUnauthenticated administrator via public WAWP REST signup: unsanitized wawp_custom_fields writes wp_capabilities through update_user_meta. Automation Web Platform plugin ≤ 4.8.6 (CVSS 3.1 9.8 Critical).
@admin · 9/25/2026CVE-2026-48842 — Roundcube Webmail Pre-Auth SQLi (virtuser_query)
highPre-authentication SQL injection in Roundcube Webmail via the virtuser_query plugin and a preg_replace() backslash escape bypass. Affects 1.6.x before 1.6.16 and 1.7.x before 1.7.1 (CVSS 3.1 8.1 HIGH).
@admin · 9/25/2026CVE-2026-12793 — JetFormBuilder ≤ 3.6.2 Unauthenticated Privilege Escalation
criticalUnauthenticated privilege escalation in the WordPress JetFormBuilder plugin (≤ 3.6.2) via the `_jet_engine_booking_form_id` handling path. Attackers may gain elevated capabilities without valid credentials.
@admin · 9/25/2026CVE-2026-89274 — WP Recipe Maker ≤ 10.8.1 Unauthenticated Shortcode Execution
highUnauthenticated arbitrary shortcode execution in WP Recipe Maker (≤ 10.8.1) through approved recipe rating comments and **reviewBody** JSON-LD handling.
@admin · 9/25/2026CVE-2026-88854 — OrdaSoft Joomla Gallery ≤ 6.2.6 Unauthenticated SQL Injection
criticalUnauthenticated SQL injection in OrdaSoft **OS Gallery** (`com_osgallery` / `com_osgallery_light` ≤ 6.2.6) via the image **search** parameter (`textsearch`).
@admin · 9/25/2026CVE-2026-13355 — Meta Box AIO ≤ 3.11.0 Unauthenticated Admin Privilege Escalation
criticalChained unauthenticated privilege escalation to **administrator** in Meta Box AIO (≤ 3.11.0) involving **MB Frontend Submission** (≤ 4.5.6) frontend submission logic.
@admin · 9/25/2026CVE-2026-19658 — Give Tributes ≤ 2.3.1 Unauthenticated PHP Object Injection
criticalUnauthenticated PHP object injection in **Give Tributes** (≤ 2.3.1) via unsanitized **eCard multi-recipient** POST data stored on donations (unsafe deserialization on read).
@admin · 9/25/2026CVE-2026-12227 — Visual Composer Website Builder ≤ 45.16.0 Unauthenticated LFI
highUnauthenticated local file inclusion in **Visual Composer Website Builder** (≤ 45.16.0) via the **`vcv-template`** parameter (public Wordfence/NVD discussion).
@admin · 9/25/2026CVE-2026-92229 — Forminator ≤ 1.57.2 Unauthenticated Shortcode Execution
highUnauthenticated arbitrary shortcode execution in **Forminator** (≤ 1.57.2) via **`current_url`** in quiz-related AJAX handlers.
@admin · 9/25/2026CVE-2026-84434 — Gravity Forms ≤ 3.1.0.4 Unauthenticated Arbitrary File Upload
criticalUnauthenticated arbitrary file upload in **Gravity Forms** (≤ 3.1.0.4) abusing a hidden **File Upload** field (`upload_file`).
@admin · 9/25/2026CVE-2026-90817 — REDCap Unauthenticated RCE (Survey __passthru / Data Import)
criticalUnauthenticated remote code execution in REDCap ≥ 13.3.0 via public survey __passthru routing and Data Import path handling. Patched in 16.0.49, 17.3.10, and 17.4.4+. Requires a valid public survey hash (s=) for the published check/exploit tooling.
@admin · 9/25/2026CVE-2026-41940 - WHM/cPanel Authentication Bypass Research Tool
criticalCritical WHM/cPanel issue (CVE-2026-41940): pre-authentication bypass chain described in public research, with CVSS ~9.8. Restrict WHM exposure and patch from vendor advisories.
@admin · 9/25/2026