#AJAX
All CosmicBytez Labs articles tagged #AJAX, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-81648: Unauthenticated Authorization Bypass in CryptoPayment Gateway WordPress Plugin
CVSS 10 flaw in CryptoPayment Gateway (≤ 1.2.2) lets anyone delete files, overwrite config, and steal cleartext wallet keys via an open AJAX endpoint.
- Security
CVE-2026-13423: Streamit WordPress Theme Allows Unauthenticated Arbitrary PHP Function Execution
The Streamit WordPress theme through version 4.5.0 exposes an unauthenticated AJAX route with no authorization or nonce verification, letting any...
- Security
CVE-2026-14894: WordPress Super Forms Plugin Critical Arbitrary File Upload
A critical unauthenticated arbitrary file upload vulnerability in the Super Forms plugin for WordPress (CVSS 9.8) allows attackers to upload and execute...
- Security
CVE-2026-12923: YouTube Showcase WordPress Plugin Arbitrary Function Call
A high-severity arbitrary function call vulnerability in the YouTube Showcase plugin allows authenticated attackers to invoke arbitrary PHP functions via...
- Security
CVE-2021-47932: WordPress TheCartPress 1.5.3.6 Privilege
TheCartPress WordPress plugin 1.5.3.6 allows unauthenticated attackers to register new administrator accounts by exploiting the AJAX handler with a...