41554 blogs · [ { "id": "01a08784-d603-701f-a921-4042c6944339", "title": "CVE-2026-7459: Simple History Subscriber+ Account Takeover (CVSS 7.5)", "url": "https://hurayraiit.com/blog/cve-2026-7459-simple-history-subscriber-account-takeover/", "published_at": "2026-06-28T00:00:00+00:00" }, { "id": "01a08784-d603-701f-a921-4042c6c93284", "title": "CVE-2026-7465: Spectra Gutenberg Blocks Contributor+ RCE (CVSS 8.8)", "url": "https://hurayraiit.com/blog/cve-2026-7465-spectra-gutenberg-blocks-contributor-rce/", "published_at": "2026-06-27T00:00:00+00:00" }, { "id": "01a08784-d603-701f-a921-4042c70673b5", "title": "CVE-2026-7537: Arbitrary File Upload in MDJM Event Management (CVSS 7.2)", "url": "https://hurayraiit.com/blog/cve-2026-7537-mdjm-arbitrary-file-upload-rce/", "published_at": "2026-06-26T00:00:00+00:00" }, { "id": "01a08784-d603-701f-a921-4042c72dccce", "title": "CVE-2026-7654: Admin Columns PHP Object Injection to RCE (CVSS 8.8)", "url": "https://hurayraiit.com/blog/cve-2026-7654-admin-columns-php-object-injection-rce/", "published_at": "2026-06-25T00:00:00+00:00" }, { "id": "01a08784-d603-701f-a921-4042c828c47d", "title": "CVE-2026-8206: Kirki Unauthenticated Account Takeover via Email Redirect (CVSS 9.8)", "url": "https://hurayraiit.com/blog/cve-2026-8206-kirki-unauthenticated-account-takeover-via-email-redirect/", "published_at": "2026-06-24T00:00:00+00:00" }, { "id": "01a08784-d603-701f-a921-4042c9191f0c", "title": "CVE-2026-8438: All-In-One Security Unauthenticated Stored XSS (CVSS 7.2)", "url": "https://hurayraiit.com/blog/cve-2026-8438-all-in-one-security-unauthenticated-stored-xss/", "published_at": "2026-06-23T00:00:00+00:00" }, { "id": "01a08784-d603-701f-a921-4042c9d3d053", "title": "CVE-2026-8809: ACF Extended Unauthenticated Privilege Escalation (CVSS 9.8)", "url": "https://hurayraiit.com/blog/cve-2026-8809-acf-extended-unauthenticated-privilege-escalation/", "published_at": "2026-06-22T00:00:00+00:00" }, { "id": "01a08784-d603-701f-a921-4042c9f5d524", "title": "CVE-2026-8901: Unauthenticated Stored XSS in Freshsales Plugin (CVSS 7.2)", "url": "https://hurayraiit.com/blog/cve-2026-8901-unauthenticated-stored-xss-freshsales-integration/", "published_at": "2026-06-21T00:00:00+00:00" }, { "id": "01a08784-d603-701f-a921-4042ca08491a", "title": "CVE-2026-9290: WP User Manager Unauthenticated Path Traversal to LFI (CVSS 7.5)", "url": "https://hurayraiit.com/blog/cve-2026-9290-wp-user-manager-unauthenticated-path-traversal-lfi/", "published_at": "2026-06-20T00:00:00+00:00" }, { "id": "01a08784-d603-701f-a921-4042ca9becc1", "title": "CVE-2026-9757: GEO my WP Unauthenticated SQL Injection (CVSS 7.5)", "url": "https://hurayraiit.com/blog/cve-2026-9757-geo-my-wp-unauthenticated-sql-injection/", "published_at": "2026-06-19T00:00:00+00:00" }, { "id": "01a08784-d603-701f-a921-4042cab78517", "title": "CVE-2026-9851: Booking Package Account Takeover via updateUser (CVSS 7.2)", "url": "https://hurayraiit.com/blog/cve-2026-9851-booking-package-account-takeover-privilege-escalation/", "published_at": "2026-06-18T00:00:00+00:00" }, { "id": "01a08784-d603-701f-a921-4042cb811a26", "title": "CVE-2026-52702: SEO Redirection Unauthenticated Stored XSS (CVSS 7.2)", "url": "https://hurayraiit.com/blog/cve-2026-52702-seo-redirection-unauthenticated-stored-xss/", "published_at": "2026-06-17T00:00:00+00:00" }, { "id": "01a08784-d603-701f-a921-4042cb88a736", "title": "CVE-2026-8719: AI Engine Privilege Escalation via MCP OAuth (CVSS 8.8)", "url": "https://hurayraiit.com/blog/cve-2026-8719-ai-engine-privilege-escalation-mcp-oauth/", "published_at": "2026-06-16T00:00:00+00:00" }, { "id": "01a08784-d603-701f-a921-4042cc2547b6", "title": "CVE-2026-9011: Ditty Plugin Exposes Non-Public Content to Anyone (CVSS 7.5)", "url": "https://hurayraiit.com/blog/cve-2026-9011-ditty-unauthenticated-information-disclosure/", "published_at": "2026-06-15T00:00:00+00:00" }, { "id": "01a08784-d603-701f-a921-4042cc4f0c9a", "title": "CVE-2026-12165: Contest Gallery Author+ Privilege Escalation (CVSS 8.8)", "url": "https://hurayraiit.com/blog/cve-2026-12165-contest-gallery-author-privilege-escalation/", "published_at": "2026-06-14T00:00:00+00:00" }, { "id": "01a08784-d603-701f-a921-4042ccca4a9b", "title": "CVE-2026-9848: WP Ticket Unauthenticated SQL Injection (CVSS 7.5)", "url": "https://hurayraiit.com/blog/cve-2026-9848-wp-ticket-unauthenticated-sql-injection/", "published_at": "2026-06-13T00:00:00+00:00" }, { "id": "01a08784-d603-701f-a921-4042cd677dd2", "title": "CVE-2026-9109: Unauthenticated Stored XSS in GPTranslate (CVSS 7.2)", "url": "https://hurayraiit.com/blog/cve-2026-9109-gptranslate-unauthenticated-stored-xss/", "published_at": "2026-06-12T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c03417ce55", "title": "CVE-2026-8071: CleanTalk Anti-Spam Unauthenticated Stored XSS (CVSS 7.2)", "url": "https://hurayraiit.com/blog/cve-2026-8071-cleantalk-antispam-unauthenticated-stored-xss/", "published_at": "2026-06-11T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c034cf59a4", "title": "CVE-2026-6379: WP Photo Album Plus Unauthenticated SQL Injection (CVSS 7.5)", "url": "https://hurayraiit.com/blog/cve-2026-6379-wp-photo-album-plus-unauthenticated-sql-injection/", "published_at": "2026-06-10T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c034f563bd", "title": "CVE-2026-5513: Bookly Unauthenticated Stored XSS via Cookie (CVSS 7.2)", "url": "https://hurayraiit.com/blog/cve-2026-5513-bookly-unauthenticated-stored-xss-via-cookie/", "published_at": "2026-06-09T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c035dff5b8", "title": "CVE-2026-42759: Stored XSS in Affiliate Super Assistent Plugin (CVSS 7.2)", "url": "https://hurayraiit.com/blog/cve-2026-42759-stored-xss-affiliate-super-assistent/", "published_at": "2026-06-08T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c036cfec10", "title": "CVE-2025-11262: Unauthenticated Stored XSS in Link Whisper Free (CVSS 7.2)", "url": "https://hurayraiit.com/blog/cve-2025-11262-link-whisper-free-unauthenticated-stored-xss/", "published_at": "2026-06-07T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c037434c1c", "title": "CVE-2026-10580: Hippoo Admin Account Takeover via REST API (CVSS 9.8)", "url": "https://hurayraiit.com/blog/cve-2026-10580-hippoo-admin-account-takeover-via-rest-api/", "published_at": "2026-06-06T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c037fa0e47", "title": "CVE-2026-10586: Essential Blocks Author+ SSRF (CVSS 7.2)", "url": "https://hurayraiit.com/blog/cve-2026-10586-essential-blocks-author-ssrf/", "published_at": "2026-06-05T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c038b4d847", "title": "CVE-2026-1829: Contributor+ RCE in Divi Builder Plugin (CVSS 8.8)", "url": "https://hurayraiit.com/blog/cve-2026-1829-content-visibility-divi-builder-contributor-rce/", "published_at": "2026-06-04T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c0391036d3", "title": "CVE-2026-27333: PHP Object Injection in PPV Live Webcams (CVSS 8.1)", "url": "https://hurayraiit.com/blog/cve-2026-27333-ppv-live-webcams-php-object-injection/", "published_at": "2026-06-03T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c0399056a9", "title": "CVE-2026-27407: AI Engine Editor+ Privilege Escalation via MCP OAuth (CVSS 7.2)", "url": "https://hurayraiit.com/blog/cve-2026-27407-ai-engine-editor-privilege-escalation-mcp-oauth/", "published_at": "2026-06-02T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c039f9bf36", "title": "CVE-2026-3655: Unauthenticated Auth Bypass in OTP Login Plugin (CVSS 9.8)", "url": "https://hurayraiit.com/blog/cve-2026-3655-otp-login-with-phone-number-auth-bypass/", "published_at": "2026-06-01T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c03a054d69", "title": "CVE-2026-42739: Advanced IP Blocker Unauthenticated Stored XSS (CVSS 7.2)", "url": "https://hurayraiit.com/blog/cve-2026-42739-advanced-ip-blocker-unauthenticated-stored-xss/", "published_at": "2026-05-31T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c03afec94e", "title": "CVE-2026-42740: Tainacan Unauthenticated SQL Injection (CVSS 7.5)", "url": "https://hurayraiit.com/blog/cve-2026-42740-tainacan-unauthenticated-sql-injection/", "published_at": "2026-05-30T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c03b2dedcf", "title": "CVE-2026-42748: Arbitrary File Upload in WPify Woo Plugin (CVSS 8.8)", "url": "https://hurayraiit.com/blog/cve-2026-42748-wpify-woo-contributor-arbitrary-file-upload/", "published_at": "2026-05-29T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c03b47a3d6", "title": "CVE-2026-42754: Favicon by RealFaviconGenerator Stored XSS (CVSS 7.2)", "url": "https://hurayraiit.com/blog/cve-2026-42754-favicon-by-realfavicongenerator-stored-xss/", "published_at": "2026-05-28T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c03c443fca", "title": "CVE-2026-42755: TableOn Unauthenticated SQL Injection (CVSS 7.5)", "url": "https://hurayraiit.com/blog/cve-2026-42755-tableon-unauthenticated-sql-injection/", "published_at": "2026-05-27T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c03cbba84c", "title": "CVE-2026-42757: WebinarIgnition Arbitrary File Deletion (CVSS 8.1)", "url": "https://hurayraiit.com/blog/cve-2026-42757-webinar-ignition-arbitrary-file-deletion/", "published_at": "2026-05-26T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c03d6ef0a4", "title": "CVE-2026-42758: WebinarIgnition Privilege Escalation (CVSS 9.8)", "url": "https://hurayraiit.com/blog/cve-2026-42758-webinarignition-unauthenticated-privilege-escalation/", "published_at": "2026-05-25T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c03d894335", "title": "CVE-2026-8679: AudioIgniter IDOR Exposes Private Playlist Data (CVSS 7.5)", "url": "https://hurayraiit.com/blog/cve-2026-8679-audioigniter-unauthenticated-idor-playlist-data-exposure/", "published_at": "2026-05-24T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c03e13f026", "title": "CVE-2026-48838: Post SMTP Unauthenticated Stored XSS (CVSS 7.2)", "url": "https://hurayraiit.com/blog/cve-2026-48838-post-smtp-unauthenticated-stored-xss/", "published_at": "2026-05-23T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c03ec76a3a", "title": "CVE-2026-48839: WP Statistics Unauthenticated Stored XSS (CVSS 7.2)", "url": "https://hurayraiit.com/blog/cve-2026-48839-wp-statistics-unauthenticated-stored-xss/", "published_at": "2026-05-22T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c03f2dcbc1", "title": "CVE-2026-5411: WP Captcha PRO Arbitrary File Upload to RCE (CVSS 8.8)", "url": "https://hurayraiit.com/blog/cve-2026-5411-wp-captcha-pro-arbitrary-file-upload-rce/", "published_at": "2026-05-21T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c03f9e1f76", "title": "CVE-2026-5415: WP Captcha PRO Authentication Bypass (CVSS 8.8)", "url": "https://hurayraiit.com/blog/cve-2026-5415-wp-captcha-pro-authentication-bypass/", "published_at": "2026-05-20T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c03fe0005a", "title": "CVE-2026-6075: Media Library Assistant CSRF in Bulk Action Forms (CVSS 8.1)", "url": "https://hurayraiit.com/blog/cve-2026-6075-media-library-assistant-csrf-bulk-action/", "published_at": "2026-05-19T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c04065ee65", "title": "CVE-2026-6403: Unauthenticated File Read in Quick Playground (CVSS 7.5)", "url": "https://hurayraiit.com/blog/cve-2026-6403-quick-playground-unauthenticated-file-read/", "published_at": "2026-05-18T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c0407d4dd5", "title": "CVE-2026-5229: Form Notify Auth Bypass via LINE OAuth Callback (CVSS 9.8)", "url": "https://hurayraiit.com/blog/cve-2026-5229-form-notify-auth-bypass-line-oauth/", "published_at": "2026-05-17T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c041471445", "title": "CVE-2026-4094: FOX Currency Switcher Config Deletion (CVSS 8.1)", "url": "https://hurayraiit.com/blog/cve-2026-4094-fox-currency-switcher-config-deletion/", "published_at": "2026-05-16T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c0422708b7", "title": "CVE-2026-3718: ManageWP Worker Unauthenticated Stored XSS (CVSS 7.2)", "url": "https://hurayraiit.com/blog/cve-2026-3718-managewp-worker-unauthenticated-stored-xss/", "published_at": "2026-05-15T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c04293d789", "title": "CVE-2026-6271: Unauthenticated RCE in Career Section Plugin (CVSS 9.8)", "url": "https://hurayraiit.com/blog/cve-2026-6271-career-section-unauthenticated-file-upload/", "published_at": "2026-05-14T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c0433f3c3d", "title": "CVE-2026-8181: Auth Bypass to Admin Takeover in Burst Statistics Plugin (CVSS 9.8)", "url": "https://hurayraiit.com/blog/cve-2026-8181-burst-statistics-auth-bypass-admin-takeover/", "published_at": "2026-05-13T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c0437bb2d7", "title": "CVE-2026-3892: Motors Plugin Arbitrary File Deletion (CVSS 8.1)", "url": "https://hurayraiit.com/blog/cve-2026-3892-motors-car-dealer-arbitrary-file-deletion/", "published_at": "2026-05-12T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c0442b7f0c", "title": "CVE-2026-5395: Fluent Forms", "url": "https://hurayraiit.com/blog/cve-2026-5395-fluent-forms-idor-exposes-form-entries/", "published_at": "2026-05-11T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c04471189c", "title": "SQA CTF 2026: The Journey, the Infra, and All 20 Challenge Walkthroughs", "url": "https://hurayraiit.com/blog/sqa-ctf-2026-the-journey-and-walkthroughs/", "published_at": "2026-05-11T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c0451ff4ed", "title": "CVE-2026-7330: Stored XSS in Auto Affiliate Links Plugin", "url": "https://hurayraiit.com/blog/cve-2026-7330-stored-xss-auto-affiliate-links/", "published_at": "2026-05-10T00:00:00+00:00" }, { "id": "01a08784-d604-7300-b1d7-c5c045b4c238", "title": "CVE-2026-6929: JoomSport Unauthenticated SQL Injection (CVSS 7.5)", "url": "https://hurayraiit.com/blog/cve-2026-6929-joomsport-unauthenticated-sql-injection/", "published_at": "2026-05-09T00:00:00+00:00" }, { "id": "01a08784-d605-70e2-ac50-0817e9998888", "title": "CVE-2026-5396: Fluent Forms Authorization Bypass via form_id (CVSS 8.2)", "url": "https://hurayraiit.com/blog/cve-2026-5396-fluent-forms-authorization-bypass-form-id/", "published_at": "2026-05-08T00:00:00+00:00" }, { "id": "01a08784-d605-70e2-ac50-0817ea3a4f81", "title": "CVE-2026-42668: Omnisend WooCommerce Account Takeover (CVSS 7.5)", "url": "https://hurayraiit.com/blog/cve-2026-42668-omnisend-woocommerce-account-takeover/", "published_at": "2026-05-07T00:00:00+00:00" }, { "id": "01a08784-d605-70e2-ac50-0817ea5e6f82", "title": "CVE-2026-4029: Unauthenticated DB Export in WP Database Backup (CVSS 7.5)", "url": "https://hurayraiit.com/blog/cve-2026-4029-unauthenticated-db-export-wp-database-backup/", "published_at": "2026-05-06T00:00:00+00:00" }, { "id": "01a08784-d605-70e2-ac50-0817ea84f02b", "title": "CVE-2026-6320: Arbitrary File Read in Salon Booking System", "url": "https://hurayraiit.com/blog/cve-2026-6320-arbitrary-file-read-salon-booking-system/", "published_at": "2026-05-05T00:00:00+00:00" }, { "id": "01a08784-d606-7337-9606-b9e26ec0f7ce", "title": "CVE-2026-5324: Unauthenticated XSS in Brizy Page Builder", "url": "https://hurayraiit.com/blog/cve-2026-5324-unauthenticated-xss-in-brizy-page-builder/", "published_at": "2026-05-04T00:00:00+00:00" }, { "id": "01a08784-d606-7337-9606-b9e26f970f19", "title": "CVE-2026-5063: Stored XSS in NEX-Forms via Form Submission", "url": "https://hurayraiit.com/blog/cve-2026-5063-stored-xss-in-nex-forms-via-form-submission/", "published_at": "2026-05-03T00:00:00+00:00" }, { "id": "01a08784-d606-7337-9606-b9e2708bd163", "title": "CVE-2026-4019: Unauthenticated Private Post Content Disclosure In Complianz Plugin", "url": "https://hurayraiit.com/blog/cve-2026-4019-complianz-private-post-content-disclosure/", "published_at": "2026-05-02T00:00:00+00:00" }, { "id": "01a08784-d606-7337-9606-b9e271669104", "title": "CVE-2026-31431: Copy Fail — A Decade-Old Linux Kernel Privilege Escalation", "url": "https://hurayraiit.com/blog/cve-2026-31431-copy-fail-linux-kernel/", "published_at": "2026-05-01T00:00:00+00:00" }, { "id": "01a08784-d606-7337-9606-b9e271da7c48", "title": "CVE-2026-6741: Critical Privilege Escalation in LatePoint Plugin (CVSS 8.8)", "url": "https://hurayraiit.com/blog/cve-2026-6741-agent-privilege-escalation-in-latepoint/", "published_at": "2026-04-30T00:00:00+00:00" }, { "id": "01a08784-d606-7337-9606-b9e2728cd502", "title": "CVE-2026-5364: Unauthenticated Arbitrary PHP Upload in CF7 Drag and Drop Plugin", "url": "https://hurayraiit.com/blog/cve-2026-5364-arbitrary-php-upload-in-cf7-drag-and-drop/", "published_at": "2026-04-29T00:00:00+00:00" }, { "id": "01a08784-d606-7337-9606-b9e272d19c6f", "title": "CVE-2026-6393: Authenticated Missing Authorization in BetterDocs Plugin", "url": "https://hurayraiit.com/blog/cve-2026-6393-missing-authorization-betterdocs-ai-write/", "published_at": "2026-04-28T00:00:00+00:00" }, { "id": "01a08784-d606-7337-9606-b9e2732fa5cc", "title": "CVE-2026-5428: Authenticated Stored XSS in Royal Elementor Addons Plugin", "url": "https://hurayraiit.com/blog/cve-2026-5428-stored-xss-in-royal-elementor-addons/", "published_at": "2026-04-27T00:00:00+00:00" }, { "id": "01a08784-d606-7337-9606-b9e273a3afc4", "title": "Mailpit: Capture & Inspect Emails Locally for WordPress, Laravel, and PHP", "url": "https://hurayraiit.com/blog/mailpit-local-email-testing-wordpress-laravel-php/", "published_at": "2026-04-26T00:00:00+00:00" }, { "id": "01a08784-d606-7337-9606-b9e2745d3e7d", "title": "CVE-2026-3844: Unauthenticated Arbitrary File Upload To RCE in Breeze Cache Plugin (CVSS 9.8)", "url": "https://hurayraiit.com/blog/cve-2026-3844-arbitrary-file-upload-breeze-cache/", "published_at": "2026-04-25T00:00:00+00:00" }, { "id": "01a08784-d606-7337-9606-b9e274bd60ab", "title": "CVE-2026-4388: Unauthenticated Stored XSS in Form Maker by 10Web Plugin", "url": "https://hurayraiit.com/blog/cve-2026-4388-unauthenticated-stored-xss-form-maker-by-10web/", "published_at": "2026-04-24T00:00:00+00:00" }, { "id": "01a08784-d606-7337-9606-b9e275597186", "title": "AI Writes the Code Now. What Happens To QA?", "url": "https://hurayraiit.com/blog/ai-writes-the-code-what-happens-to-qa/", "published_at": "2026-04-23T00:00:00+00:00" }, { "id": "01a08784-d606-7337-9606-b9e275aa0bd8", "title": "CVE-2026-5718: Unauthenticated File Upload To RCE in DnD Upload CF7 Plugin", "url": "https://hurayraiit.com/blog/cve-2026-5718-unauthenticated-file-upload-dnd-upload-cf7/", "published_at": "2026-04-22T00:00:00+00:00" }, { "id": "01a08784-d606-7337-9606-b9e276553969", "title": "CVE-2026-2262: Easy Appointments Data Exposure via REST API", "url": "https://hurayraiit.com/blog/cve-2026-2262-easy-appointments-data-exposure-via-rest-api/", "published_at": "2026-04-21T00:00:00+00:00" }, { "id": "01a08784-d606-7337-9606-b9e276e27134", "title": "CVE-2026-5478: Path Traversal File Read in Everest Forms", "url": "https://hurayraiit.com/blog/cve-2026-5478-path-traversal-file-read-in-everest-forms/", "published_at": "2026-04-20T00:00:00+00:00" }, { "id": "01a08784-d606-7337-9606-b9e2774536d6", "title": "CVE-2025-14868: CSRF File Deletion in Career Section Plugin", "url": "https://hurayraiit.com/blog/cve-2025-14868-csrf-file-deletion-career-section/", "published_at": "2026-04-19T00:00:00+00:00" }, { "id": "01a08784-d606-7337-9606-b9e27773e575", "title": "CVE-2026-2834: Unauthenticated Stored XSS in Token of Trust Plugin", "url": "https://hurayraiit.com/blog/cve-2026-2834-unauthenticated-stored-xss-in-token-of-trust/", "published_at": "2026-04-18T00:00:00+00:00" }, { "id": "01a08784-d606-7337-9606-b9e27774b7c2", "title": "CVE-2026-4365: Arbitrary Quiz Answer Deletion in LearnPress (CVSS 9.1)", "url": "https://hurayraiit.com/blog/cve-2026-4365-arbitrary-quiz-answer-deletion-in-learnpress/", "published_at": "2026-04-17T00:00:00+00:00" }, { "id": "01a08784-d606-7337-9606-b9e277e34981", "title": "CVE-2026-5231: Stored XSS via utm_source in WP Statistics", "url": "https://hurayraiit.com/blog/cve-2026-5231-stored-xss-via-utm-source-in-wp-statistics/", "published_at": "2026-04-16T00:00:00+00:00" }, { "id": "01a08784-d607-727c-a49f-c66e6d461027", "title": "CVE-2026-4880: Barcode Scanner Plugin Privilege Escalation", "url": "https://hurayraiit.com/blog/cve-2026-4880-barcode-scanner-privilege-escalation/", "published_at": "2026-04-15T00:00:00+00:00" }, { "id": "01a08784-d607-727c-a49f-c66e6d925fee", "title": "CVE-2026-3017: PHP Object Injection in Smart Post Show", "url": "https://hurayraiit.com/blog/cve-2026-3017-php-object-injection-smart-post-show/", "published_at": "2026-04-14T00:00:00+00:00" }, { "id": "01a08784-d607-727c-a49f-c66e6e6c40c6", "title": "CVE-2025-15027: Privilege Escalation in JAY Login & Register (CVSS 9.8)", "url": "https://hurayraiit.com/blog/cve-2025-15027-privilege-escalation-jay-login-register/", "published_at": "2026-04-13T00:00:00+00:00" }, { "id": "01a08784-d607-727c-a49f-c66e6ea9b0f4", "title": "CVE-2025-68043: Missing Authorization in LottieFiles Plugin (CVSS 9.8)", "url": "https://hurayraiit.com/blog/cve-2025-68043-missing-authorization-in-lottiefiles-plugin/", "published_at": "2026-04-12T00:00:00+00:00" }, { "id": "01a08784-d607-727c-a49f-c66e6ed7ee7a", "title": "CVE-2026-3124: Download Monitor Unauthenticated IDOR To Order Theft", "url": "https://hurayraiit.com/blog/cve-2026-3124-download-monitor-unauthenticated-order-theft/", "published_at": "2026-04-11T00:00:00+00:00" }, { "id": "01a08784-d607-727c-a49f-c66e6f1181b4", "title": "CVE-2026-3360: Tutor LMS Unauthenticated Billing Overwrite (CVSS 7.5)", "url": "https://hurayraiit.com/blog/cve-2026-3360-tutor-lms-unauthenticated-billing-overwrite/", "published_at": "2026-04-10T00:00:00+00:00" }, { "id": "01a08784-d607-727c-a49f-c66e6f3e7e67", "title": "CVE-2026-3296: PHP Object Injection in Everest Forms (CVSS 9.8)", "url": "https://hurayraiit.com/blog/cve-2026-3296-everest-forms-unauthenticated-php-object-injection/", "published_at": "2026-04-09T00:00:00+00:00" }, { "id": "01a08784-d607-727c-a49f-c66e6f8f6c3c", "title": "CVE-2026-2942: Arbitrary File Upload in ProSolution WP Client", "url": "https://hurayraiit.com/blog/cve-2026-2942-prosolution-wp-client-arbitrary-file-upload/", "published_at": "2026-04-08T00:00:00+00:00" }, { "id": "01a08784-d607-727c-a49f-c66e6fbc7510", "title": "CVE-2026-4003: CVSS 9.8 Privilege Escalation in Users Manager PN", "url": "https://hurayraiit.com/blog/cve-2026-4003-wordpress-users-manager-pn-privilege-escalation/", "published_at": "2026-04-07T00:00:00+00:00" }, { "id": "01a08784-d607-727c-a49f-c66e704b82eb", "title": "CVE-2025-15488: Unauthenticated Code Injection in Responsive Plus", "url": "https://hurayraiit.com/blog/cve-2025-15488-unauthenticated-code-injection-responsive-plus/", "published_at": "2026-04-06T00:00:00+00:00" }, { "id": "01a08784-d607-727c-a49f-c66e7128316b", "title": "Cloudinary AI Skill for SQA: Auto-Upload Screenshots Explained", "url": "https://hurayraiit.com/blog/cloudinary-ai-skill-for-sqa-engineers/", "published_at": "2026-04-05T00:00:00+00:00" }, { "id": "01a08784-d607-727c-a49f-c66e7181da65", "title": "CVE-2026-1233: Hardcoded MySQL Credentials in TTS Plugin", "url": "https://hurayraiit.com/blog/cve-2026-1233-text-to-speech-tts-hardcoded-credentials/", "published_at": "2026-04-04T00:00:00+00:00" }, { "id": "01a08784-d607-727c-a49f-c66e725d67ca", "title": "axios Supply Chain Attack: Malicious Versions Deploy a RAT", "url": "https://hurayraiit.com/blog/npm-supply-chain-attack-axios-malicious-versions-1-14-1-and-0-30-4/", "published_at": "2026-04-03T00:00:00+00:00" }, { "id": "01a08784-d607-727c-a49f-c66e734e941f", "title": "CVE-2026-5130: Debugger & Troubleshooter Unauthenticated Account Takeover", "url": "https://hurayraiit.com/blog/cve-2026-5130-debugger-troubleshooter-account-takeover/", "published_at": "2026-04-02T00:00:00+00:00" }, { "id": "01a08784-d607-727c-a49f-c66e735a089f", "title": "Hello, World", "url": "https://hurayraiit.com/blog/01-hello/", "published_at": "2026-04-01T00:00:00+00:00" }, { "id": "01a08784-d607-727c-a49f-c66e7423fc8d", "title": "CVE-2026-4267: Unauthenticated Reflected XSS in Query Monitor Plugin", "url": "https://hurayraiit.com/blog/cve-2026-4267-reflected-xss-in-query-monitor/", "published_at": "2026-03-31T00:00:00+00:00" }, { "id": "01a08784-d607-727c-a49f-c66e74cb204a", "title": "CVE-2026-4257: SSTI to RCE in Contact Form by Supsystic", "url": "https://hurayraiit.com/blog/cve-2026-4257-contact-form-by-supsystic-ssti-rce/", "published_at": "2026-03-30T00:00:00+00:00" }, { "id": "01a08784-d607-727c-a49f-c66e75860488", "title": "CVE-2026-4987: Unauthenticated Payment Bypass in SureForms", "url": "https://hurayraiit.com/blog/cve-2026-4987-unauthenticated-payment-bypass-in-sureforms/", "published_at": "2026-03-29T00:00:00+00:00" }, { "id": "01a08784-d607-727c-a49f-c66e75bbaa68", "title": "CVE-2026-3584: Kali Forms Unauthenticated RCE & Admin Takeover", "url": "https://hurayraiit.com/blog/cve-2026-3584-kali-forms-unauthenticated-rce-admin-takeover/", "published_at": "2026-03-28T00:00:00+00:00" }, { "id": "01a08784-d607-727c-a49f-c66e75ec33b8", "title": "CVE-2026-1357: Unauthenticated RCE in WPvivid Backup Plugin (CVSS 9.8)", "url": "https://hurayraiit.com/blog/cve-2026-1357-unauthenticated-rce-wpvivid-backup/", "published_at": "2026-03-02T00:00:00+00:00" }, { "id": "01a08784-d607-727c-a49f-c66e767d5511", "title": "CVE-2026-27384: Unauthenticated RCE in W3 Total Cache", "url": "https://hurayraiit.com/blog/cve-2026-27384-w3-total-cache-unauthenticated-rce/", "published_at": "2026-03-01T00:00:00+00:00" }, { "id": "01a08784-d607-727c-a49f-c66e768cfdba", "title": "কীভাবে ভোট জালিয়াতি করবেন?", "url": "https://hurayraiit.com/blog/kivabe-vote-jaliyati-korben/", "published_at": "2026-02-09T00:00:00+00:00" }, { "id": "01a08784-d607-727c-a49f-c66e7759f5c1", "title": "Zikr When Waking Up - ঘুম থেকে জেগে উঠার সময়ের যিক্‌রসমূহ", "url": "https://hurayraiit.com/blog/zikr-when-waking-up/", "published_at": "2026-01-27T00:00:00+00:00" }, { "id": "01a08784-d607-727c-a49f-c66e7767f64f", "title": "The Excellence of Zikr - যিক্‌রের ফযীলত", "url": "https://hurayraiit.com/blog/the-excellence-of-zikr/", "published_at": "2026-01-26T00:00:00+00:00" }, { "id": "01a08784-d607-727c-a49f-c66e780843b1", "title": "সূরা আলে ইমরানের শিক্ষাসমূহ", "url": "https://hurayraiit.com/blog/lessons-from-surah-al-imran/", "published_at": "2026-01-16T00:00:00+00:00" } ] posts Claim your blog
Back to hurayraiit.com
Blog · corpus.blog/blogs/hurayraiit.com/posts

hurayraiit.com

hurayraiit.com

2026