██▀▀▀▀▀█ ██▀▀▀▀▀█ ██▀▀▀▀▀█ ██▀▀▀▀▀█ ██ ▄▄▀ ██▀▀▀▀▀█
▒█ ▒█▀▀▀ ▒█ ▒█ ▒█ ▒█▀▀▀ ▒█ ▒█▀▀▀▀▄ ▒█▀▀▀ ▒█
▓▓ ▓▓ ▓▓ ▓▓ ▓▓ ▓▓ ▓▓ ▓▓ ▓▓ ▓▓ ▓▓
█▒ █▒ █▒ █▒ █▒ █▒ █▒ █▒ █▒ █▒ █▒
▓░ ▓░ ▓░ ▓░ ▓░ ▓░ ▓░ ▓░ ▓░ ▓░ ▓░
▒█ ▒█ ▒█ ▒█ ▒█ ▒█ ▒█ ▒█ ▒█ ▒█ ▒█
░▓ ░▓ ░▓ ░▓ ░▓ ░▓ ░▓ ░▓ ░▓ ░▓ ░▓
▒ ▒ ▒ ▒ ▒ ▒ ▒ ▒ ▒ ▒ ▒
▀▀ ▀▀ ▀▀ ▀▀ ▀▀ ▀▀ ▀▀ ▀▀ ▀▀ ▀▀ ▀▀
tanaka | @tanakz
offensive security researcher.
welcome to my zone! here, i share some research and studies on cybersecurity. :)
latest post: CVE-2026-82221 - Unauthenticated Reflected Cross-Site Scripting (XSS) in the WordPress RegistrationMagic plugin
CVE-2026-82221 was recently published, an unauthenticated XSS vulnerability I discovered in the WordPress RegistrationMagic plugin, affecting plugin versions <= 6.0.9.8. In this article, I intend to provide a detailed analysis of the vulnerability, including its root cause, potential impact, and its proof of concept.
articles:
- [ 2026-09-02 ] CVE-2026-82221 - Unauthenticated Reflected Cross-Site Scripting (XSS) in the WordPress RegistrationMagic plugin #research #cve #xss
- [ 2026-08-14 ] From ESC4 to Domain Admin: exploiting vulnerable templates in AD CS #writeup #active-directory