RSSAmplifier

Blog

Abu Hurayra

Security engineer and SDET. Writing about application security, test automation, and the open-source web.

hurayraiit.comRSS feed ↗181 posts

Latest posts

CVE-2026-7459: Simple History Subscriber+ Account Takeover (CVSS 7.5)

CVE-2026-7459 (CVSS 7.5) in Simple History <= 5.26.0 allows a Subscriber to read admin password reset links and take over administrator accounts.

CVE-2026-7465: Spectra Gutenberg Blocks Contributor+ RCE (CVSS 8.8)

CVE-2026-7465: CVSS 8.8 RCE in Spectra Gutenberg Blocks. Contributor+ attackers call arbitrary PHP functions via crafted block attributes.

CVE-2026-7537: Arbitrary File Upload in MDJM Event Management (CVSS 7.2)

CVE-2026-7537 is a CVSS 7.2 High severity Arbitrary File Upload vulnerability in the MDJM Event Management WordPress plugin (<= 1.7.8.3) that lets an authenticated administrator upload PHP webshells and execute remote code.

CVE-2026-7654: Admin Columns PHP Object Injection to RCE (CVSS 8.8)

CVE-2026-7654 is a CVSS 8.8 PHP Object Injection flaw in Admin Columns that lets a Contributor trigger RCE by injecting a serialized object into a custom post meta field.

CVE-2026-8206: Kirki Unauthenticated Account Takeover via Email Redirect (CVSS 9.8)

CVE-2026-8206 (CVSS 9.8) in Kirki plugin 6.0.0–6.0.6 lets unauthenticated attackers redirect password reset emails to steal any WordPress account.

CVE-2026-8438: All-In-One Security Unauthenticated Stored XSS (CVSS 7.2)

CVE-2026-8438 is a CVSS 7.2 unauthenticated stored XSS in All-In-One Security (AIOS) for WordPress. Attackers can inject scripts that run in an admin's browser.

CVE-2026-8809: ACF Extended Unauthenticated Privilege Escalation (CVSS 9.8)

CVE-2026-8809 (CVSS 9.8) — unauthenticated privilege escalation in ACF Extended <= 0.9.2.5 lets any visitor create a WordPress administrator account.

CVE-2026-8901: Unauthenticated Stored XSS in Freshsales Plugin (CVSS 7.2)

CVE-2026-8901 is a CVSS 7.2 unauthenticated stored XSS in Integration for Freshsales ≤1.0.15. A crafted form entry runs JavaScript in the admin's browser.

CVE-2026-9290: WP User Manager Unauthenticated Path Traversal to LFI (CVSS 7.5)

CVE-2026-9290 (CVSS 7.5): Unauthenticated Path Traversal to LFI in WP User Manager <= 2.9.17 via the unvalidated 'tab' query parameter.

CVE-2026-9757: GEO my WP Unauthenticated SQL Injection (CVSS 7.5)

CVE-2026-9757: CVSS 7.5 unauthenticated SQL injection in GEO my WP <=4.5.5. Any visitor can extract sensitive database data via map boundary parameters.

CVE-2026-9851: Booking Package Account Takeover via updateUser (CVSS 7.2)

CVE-2026-9851 is a CVSS 7.2 privilege escalation in the Booking Package WordPress plugin. Editor+ users can take over any admin account via updateUser action.

CVE-2026-52702: SEO Redirection Unauthenticated Stored XSS (CVSS 7.2)

CVE-2026-52702 (CVSS 7.2): Unauthenticated stored XSS in SEO Redirection <= 9.17 via spoofed IP headers — scripts execute in the admin 404 Errors page.

CVE-2026-8719: AI Engine Privilege Escalation via MCP OAuth (CVSS 8.8)

CVE-2026-8719 (CVSS 8.8) lets any Subscriber invoke admin-level MCP tools in AI Engine 3.4.9, including creating administrator accounts.

CVE-2026-9011: Ditty Plugin Exposes Non-Public Content to Anyone (CVSS 7.5)

CVE-2026-9011 is a CVSS 7.5 (High) Missing Authorization vulnerability in the Ditty WordPress plugin that lets anyone read non-public Ditty content.

CVE-2026-12165: Contest Gallery Author+ Privilege Escalation (CVSS 8.8)

CVE-2026-12165 is a CVSS 8.8 High privilege escalation in Contest Gallery <= 30.0.2 allowing Authors to promote Google sign-in accounts to Administrator.

CVE-2026-9848: WP Ticket Unauthenticated SQL Injection (CVSS 7.5)

CVE-2026-9848 is a CVSS 7.5 SQL Injection vulnerability in WP Ticket ≤ 6.0.4. An unauthenticated attacker can extract any data from the database via the WordPress search parameter.

CVE-2026-9109: Unauthenticated Stored XSS in GPTranslate (CVSS 7.2)

CVE-2026-9109 is a CVSS 7.2 Unauthenticated Stored XSS in GPTranslate. The API key is predictable, so any visitor can inject scripts via the REST API.

CVE-2026-8071: CleanTalk Anti-Spam Unauthenticated Stored XSS (CVSS 7.2)

CVE-2026-8071 (CVSS 7.2): Stored XSS in CleanTalk Anti-Spam plugin < 6.79 lets unauthenticated attackers inject scripts via email encoder shortcode bypass.

CVE-2026-6379: WP Photo Album Plus Unauthenticated SQL Injection (CVSS 7.5)

CVE-2026-6379 is a CVSS 7.5 (High) unauthenticated SQL injection in WP Photo Album Plus <= 9.1.10.011. Any visitor can extract sensitive data from the database without logging in.

CVE-2026-5513: Bookly Unauthenticated Stored XSS via Cookie (CVSS 7.2)

CVE-2026-5513: a CVSS 7.2 unauthenticated stored XSS in the Bookly WordPress plugin. The bookly-customer-full-name cookie renders unescaped on the booking form.

CVE-2026-42759: Stored XSS in Affiliate Super Assistent Plugin (CVSS 7.2)

CVE-2026-42759 (CVSS 7.2): Stored XSS in Affiliate Super Assistent <= 1.10.1 lets unauthenticated attackers execute scripts in the admin browser.

CVE-2025-11262: Unauthenticated Stored XSS in Link Whisper Free (CVSS 7.2)

CVE-2025-11262 is a CVSS 7.2 High severity Unauthenticated Stored XSS in Link Whisper Free. Any visitor can poison a REST endpoint to inject scripts that run in every admin's browser.

CVE-2026-10580: Hippoo Admin Account Takeover via REST API (CVSS 9.8)

CVE-2026-10580 (CVSS 9.8): critical auth bypass in Hippoo WooCommerce plugin lets unauthenticated attackers reset any user password and take over the site.

CVE-2026-10586: Essential Blocks Author+ SSRF (CVSS 7.2)

CVE-2026-10586: CVSS 7.2 SSRF in Essential Blocks ≤ 6.1.3 lets Author-level users force the server to probe internal hosts via the AI image save action.

CVE-2026-1829: Contributor+ RCE in Divi Builder Plugin (CVSS 8.8)

CVE-2026-1829: CVSS 8.8 Code Injection in Content Visibility for Divi Builder <=4.02 lets Contributors execute arbitrary PHP on the server.

CVE-2026-27333: PHP Object Injection in PPV Live Webcams (CVSS 8.1)

CVE-2026-27333 (CVSS 8.1): PHP Object Injection in PPV Live Webcams <=7.3.23 allows unauthenticated attackers to inject PHP objects. Fixed in 7.3.24.

CVE-2026-27407: AI Engine Editor+ Privilege Escalation via MCP OAuth (CVSS 7.2)

CVE-2026-27407 (CVSS 7.2) affects AI Engine ≤ 3.4.9. An Editor can exploit the MCP OAuth flow to get a token and escalate their role to administrator.

CVE-2026-3655: Unauthenticated Auth Bypass in OTP Login Plugin (CVSS 9.8)

CVE-2026-3655 (CVSS 9.8): Critical authentication bypass in OTP Login With Phone Number plugin <= 1.8.60. Attackers log in as any user, including admins, without credentials.

CVE-2026-42739: Advanced IP Blocker Unauthenticated Stored XSS (CVSS 7.2)

CVE-2026-42739 is a CVSS 7.2 High Stored XSS in Advanced IP Blocker (≤8.10.7) where unauthenticated attackers inject malicious scripts that execute in the admin panel.

CVE-2026-42740: Tainacan Unauthenticated SQL Injection (CVSS 7.5)

CVE-2026-42740: CVSS 7.5 SQL injection in Tainacan ≤ 1.0.3 allows unauthenticated attackers to extract sensitive data from the WordPress database.

CVE-2026-42748: Arbitrary File Upload in WPify Woo Plugin (CVSS 8.8)

CVE-2026-42748 is a CVSS 8.8 Arbitrary File Upload flaw in WPify Woo <= 5.4.1 letting Contributors upload PHP shells and potentially execute remote code.

CVE-2026-42754: Favicon by RealFaviconGenerator Stored XSS (CVSS 7.2)

CVE-2026-42754 is a CVSS 7.2 High Stored XSS in Favicon by RealFaviconGenerator <= 1.3.46 that lets attackers inject scripts via SSRF into the admin panel.

CVE-2026-42755: TableOn Unauthenticated SQL Injection (CVSS 7.5)

CVE-2026-42755 is a CVSS 7.5 unauthenticated SQL injection in TableOn – WordPress Posts Table Filterable <= 1.0.5.1 that lets any visitor extract sensitive data from the database.

CVE-2026-42757: WebinarIgnition Arbitrary File Deletion (CVSS 8.1)

CVE-2026-42757 is a CVSS 8.1 arbitrary file deletion flaw in WebinarIgnition. Subscribers can delete any file, leading to remote code execution.

CVE-2026-42758: WebinarIgnition Privilege Escalation (CVSS 9.8)

CVE-2026-42758 is a CVSS 9.8 Critical unauthenticated privilege escalation in WebinarIgnition. Any visitor can create a WordPress account with manage_options access.

CVE-2026-8679: AudioIgniter IDOR Exposes Private Playlist Data (CVSS 7.5)

CVE-2026-8679 is a CVSS 7.5 High severity Unauthenticated IDOR in AudioIgniter Music Player <= 2.0.2 that lets any visitor read private, draft, or trashed playlist track metadata.

CVE-2026-48838: Post SMTP Unauthenticated Stored XSS (CVSS 7.2)

CVE-2026-48838 is a CVSS 7.2 High Unauthenticated Stored XSS in Post SMTP <= 3.6.2. An attacker injects a script via any email-triggering form; it fires when an admin views the email log.

CVE-2026-48839: WP Statistics Unauthenticated Stored XSS (CVSS 7.2)

CVE-2026-48839 is a CVSS 7.2 Stored XSS in WP Statistics <= 14.16.6. Any visitor can inject scripts into admin pages by sending a crafted User-Agent header.

CVE-2026-5411: WP Captcha PRO Arbitrary File Upload to RCE (CVSS 8.8)

CVE-2026-5411 (CVSS 8.8): WP Captcha PRO ≤ 5.38 lets Subscriber users upload PHP webshells via the licensing module, enabling remote code execution.

CVE-2026-5415: WP Captcha PRO Authentication Bypass (CVSS 8.8)

CVE-2026-5415 is a CVSS 8.8 authentication bypass in WP Captcha PRO. A Subscriber-level user can log in as any administrator via temporary login links.

CVE-2026-6075: Media Library Assistant CSRF in Bulk Action Forms (CVSS 8.1)

CVE-2026-6075 is a CVSS 8.1 High CSRF vulnerability in Media Library Assistant <= 3.35 that lets attackers trick admins into deleting, editing, or purging plugin settings and attachment metadata.

CVE-2026-6403: Unauthenticated File Read in Quick Playground (CVSS 7.5)

CVE-2026-6403 (CVSS 7.5) is a path traversal vulnerability in Quick Playground that lets unauthenticated attackers ZIP and download arbitrary server files.

CVE-2026-5229: Form Notify Auth Bypass via LINE OAuth Callback (CVSS 9.8)

CVE-2026-5229 (CVSS 9.8 Critical): auth bypass in Form Notify ≤ 1.1.10. Any visitor can hijack any WordPress account, including admin, via LINE OAuth.

CVE-2026-4094: FOX Currency Switcher Config Deletion (CVSS 8.1)

CVE-2026-4094 (CVSS 8.1): Missing Authorization in FOX Currency Switcher for WooCommerce lets Contributors delete the multi-currency config.

CVE-2026-3718: ManageWP Worker Unauthenticated Stored XSS (CVSS 7.2)

CVE-2026-3718 is a CVSS 7.2 High stored XSS flaw in ManageWP Worker ≤ 4.9.31 that lets unauthenticated attackers inject malicious scripts into the admin.

CVE-2026-6271: Unauthenticated RCE in Career Section Plugin (CVSS 9.8)

CVE-2026-6271 scores CVSS 9.8 Critical in Career Section (≤ 1.7) — unauthenticated attackers can upload PHP files and execute arbitrary server-side code.

CVE-2026-8181: Auth Bypass to Admin Takeover in Burst Statistics Plugin (CVSS 9.8)

CVE-2026-8181 is a CVSS 9.8 Critical authentication bypass in Burst Statistics 3.4.0–3.4.1.1. An unauthenticated attacker with any admin username can mint a WordPress Application Password and take over the admin account.

CVE-2026-3892: Motors Plugin Arbitrary File Deletion (CVSS 8.1)

CVE-2026-3892 is a CVSS 8.1 High severity arbitrary file deletion vulnerability in the Motors WordPress plugin. Any subscriber can delete critical server files including wp-config.php.

CVE-2026-5395: Fluent Forms <= 6.2.0 IDOR Exposes Form Entries (CVSS 8.2)

CVE-2026-5395 (CVSS 8.2) is an IDOR in Fluent Forms <= 6.2.0. Authenticated users can bypass per-form access controls and export any form's submissions.

SQA CTF 2026: The Journey, the Infra, and All 20 Challenge Walkthroughs

How I built and ran a 72-hour CTF for 79 active QA participants — the prep, the infra, the results portal, and full walkthroughs for every challenge.