The WooPayments: Integrated WooCommerce Payments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_upe_appearance_ajax' function in all versions up to, and including, 10.5.1. This makes it possible for unauthenticated attackers to update plugin settings.
[POC] CVE-2026-17106 — POC-CopyEscape-CVE-2026-17106
PoC funcional de CVE-2026-17106 (CopyEscape): carrera TOCTOU en docker cp que permite escritura arbitraria en el host Docker. Laboratorio Docker + monitor inotify + LD_PRELOAD. Variante macOS inocua y Linux destructiva.
[POC] CVE-2026-17106 — CVE-2026-17106
CopyEscape (CVE-2026-17106) docker cp container-to-host arbitrary file write PoC mirror — Imperva Ron Masas, MIT; for authorized security testing
[POC] CVE-2026-17106 — CopyEscape-CVE-2026-17106
PoC repository for the blog post CopyEscape: Taking Over Docker Hosts with docker cp
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free