The Sports Club Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before' and 'after' attributes of the `scm_member_data` shortcode in all versions up to, and including, 1.12.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
[POC] CVE-2026-48710 — supply-chain-guard
Detect, assess, and respond to supply chain attacks across npm/yarn and Python (pip/poetry/uv). Claude Code skill + standalone scripts. Built during axios RAT (2026-03-31) and Starlette BadHost CVE-2026-48710 (2026-05-22).
[POC] CVE-2026-48710 — BadHost-CVE-2026-48710-Exploit
Detection scanner for CVE-2026-48710 - Host-header auth bypass in Starlette/FastAPI
[POC] CVE-2026-48710 — starlette-host-header-lab
Starlette Host-Header URL Confusion Lab (X41-2026-002) - CVE-2026-48710
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free