Blog
What I test first, where authorization checks fail and how small implementation details become useful attack paths.
- Finding CVEs in WordPress: CVE-2026-39531, SQL injection in WP Directory Kit
- Finding CVEs in WordPress: CVE-2026-39513, exposed appointments in Easy Appointments
- Nobody opens the documents