CVE-2026-78259 - WPLegalPages API Secret Disclosure and Account Disconnect via Unauthenticated REST API
Unauthenticated WPLegalPages <= 3.6.4 REST endpoints disclose API secrets and allow attackers to disconnect the connected account.
Unauthenticated WPLegalPages <= 3.6.4 REST endpoints disclose API secrets and allow attackers to disconnect the connected account.
CSS injection and browser side-channel exfiltration leak the flag from the approval bot.
Vite CVE-2025-30208 bypasses the dev server allow list and exposes arbitrary files through /@fs/.
DOM Clobbering bypasses the sanitizer and enables file-name disclosure followed by flag read.
Client-side privilege escalation and SQL injection lead to the administrator account and flag.
Double URL encoding bypasses an absolute-path filter and enables local file read.
Path traversal in the mod build flow writes a Python codec payload and reaches server-side code execution.
Jinja2 SSTI bypasses a blacklist, reaches RCE, and reads the challenge flag.
Broken access control in Events Made Easy <= 3.0.67 lets unauthenticated attackers modify arbitrary person records through the public personal-information AJAX endpoint.
Unauthenticated SQL injection in WPDM Premium Packages <= 6.2.0 exposes the public Mini Cart coupon REST endpoint to blind time-based database extraction.
Unauthenticated webhook forgery in Peach Payments Gateway <= 4.0.2 lets attackers mark pending WooCommerce orders as paid by submitting a forged successful payment result.
Stored XSS in reCAPTCHA for Asgaros Forum <= 1.1.0 lets a low-privilege Subscriber inject JavaScript through the reCAPTCHA site key rendered in the forum editor.
Broken authentication in Colissimo Officiel <= 2.9.0 exposes shipping-rate import/export actions to unauthenticated visitors via the shared admin-ajax dispatcher.
CTF writeup - web/Ganzir (OmniCTF 2026)
CTF writeup - web/StayWild (OmniCTF 2026)
CTF writeup - web_<_w+ (SekaiCTF 2026)
CTF writeup - web/migurimental (SekaiCTF 2026)
IDOR in SupportCandy <= 3.4.6 lets a low-privilege user reassign and download another user's private ticket attachments via the thread-creation endpoint.
Broken access control in Newsletters <= 4.13 lets an unauthenticated attacker take over any subscriber's management account via a predictable md5(id) token.
Broken authentication in Melhor Envio <= 2.16.3 lets a low-privilege Subscriber read and overwrite the store's Melhor Envio API tokens.
Broken authentication in Masteriyo LMS 2.1.8 allows unauthenticated attackers to forge Lemon Squeezy webhooks and mark pending orders as paid.
CTF writeup - cookoff (GPNCTF 2026)
CTF writeup - Fancy Food Notifications (GPNCTF 2026)
CTF writeup - Pharry (GPNCTF 2026)
CTF writeup - recipeloader (GPNCTF 2026)
CTF writeup - restaurant-builder (GPNCTF 2026)
CTF writeup - SecretPickle (GPNCTF 2026)
CTF writeup - Secure Secretpickle (GPNCTF 2026)
CTF writeup - Simple food notifications (GPNCTF 2026)
CTF writeup - web/chained (TJCTF 2026)
CTF writeup - web/free-cloud-storage (TJCTF 2026)
CTF writeup - web/paper-trail (TJCTF 2026)
CTF writeup - web/treasure-hunt (TJCTF 2026)
CTF writeup - web/Vibed Intranet Part 1&2 (TJCTF 2026)
CTF writeup - web/vibecoded (TJCTF 2026)
CTF writeup - Brick by Brick (UMassCTF 2026)
CTF writeup - BrOWSER BOSS FIGHT (UMassCTF 2026)
CTF writeup - ORDER66 (UMassCTF 2026)
CTF writeup - Break the Bank (UTCTF 2026)
CTF writeup - Crab Mentality (UTCTF 2026)
CTF writeup - Time to Pretend (UTCTF 2026)