I am Mattia Brollo, aka 0xbro, a penetration tester, vulnerability researcher, content creator & wannabe ethical hacker. Within the blog you can find all my writeups about vulnerability research, CTFs tricks, exploits, templates, hints and penetration testing notes.
WordPress plugin "Profile Builder Pro" (versions before 3.14.5) is susceptible to Unauthenticated PHP Object Injection (CVE-2026-7647). In this blog post, we discuss how we discovered and exploited the vulnerability using a novel POP chain, how AI helped in the process, taking a final look at targets in the wild.
Introduction Happy 2026, two months late and with a new design for my blog! 🥳 It had been quite a while since I last posted anything on my blog, and recently I have been trying to find a functional system to best consume and process online information. So here we are, writing a blog post that will allow me to clarify my ideas (hopefullyspoiler, it did!) and at the same time give you some ins...
Multiple vulnerabilities in vtenext 25.02.1 and prior versions allow unauthenticated attackers to bypass authentication through three separate vectors, ultimately leading to remote code execution on the underlying server.
The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access and modification of data| due to a misconfigured capability check on the 'pda_lite_custom_permission_check' function in versions 2.8.6 to 2.8.8.2. This makes it possible for authenticated attackers, with Contributor-level access and above, to access and change the protection status of…
Having well-organized notes is crucial for penetration testing, OSCP preparation and exams, CTFs, etc. They help you quickly identify previously exploited vulnerabilities and map the interconnections between machines within a network. In this video, I'll show you how I take effective notes using Obsidian's Canvas and Excalidraw, and how I structure them.