Polosss
6 exploits
Active since Jun 2026
Simple File List <= 6.3.7 - Missing Authorization to Unauthenticated File Modification via simplefilelist_edit_job AJAX Action
BetterDocs Pro <= 3.8.0 - Unauthenticated Local File Inclusion via doc_style
Hippoo Mobile App for WooCommerce <= 1.9.4 - Unauthenticated Authentication Bypass to Administrator Account Takeover via REST API
Branda – White Label & Branding, Free Login Page Customizer <= 3.4.29 - Unauthenticated Privilege Escalation via Account Takeover
CVSS 9.8
Schema & Structured Data for WP & AMP < 1.60 - Unauthenticated Arbitrary Media Upload
CVSS 9.1
WordPress Insert PHP Plugin 4.7.0 PHP Code Injection via REST API
CVSS 9.8