██▀▀▀▀▀█ ██▀▀▀▀▀█ ██▀▀▀▀▀█ ██▀▀▀▀▀█ ██   ▄▄▀ ██▀▀▀▀▀█
      ▒█ ▒█▀▀▀ ▒█ ▒█    ▒█ ▒█▀▀▀ ▒█ ▒█▀▀▀▀▄  ▒█▀▀▀ ▒█
      ▓▓ ▓▓    ▓▓ ▓▓    ▓▓ ▓▓    ▓▓ ▓▓    ▓▓ ▓▓    ▓▓
      █▒ █▒    █▒ █▒    █▒ █▒    █▒ █▒    █▒ █▒    █▒
      ▓░ ▓░    ▓░ ▓░    ▓░ ▓░    ▓░ ▓░    ▓░ ▓░    ▓░
      ▒█ ▒█    ▒█ ▒█    ▒█ ▒█    ▒█ ▒█    ▒█ ▒█    ▒█
      ░▓ ░▓    ░▓ ░▓    ░▓ ░▓    ░▓ ░▓    ░▓ ░▓    ░▓
       ▒  ▒     ▒  ▒     ▒  ▒     ▒  ▒     ▒  ▒     ▒
      ▀▀ ▀▀    ▀▀ ▀▀    ▀▀ ▀▀    ▀▀ ▀▀    ▀▀ ▀▀    ▀▀

tanaka | @tanakz

offensive security researcher.

welcome to my zone! here, i share some research and studies on cybersecurity. :)

latest post: CVE-2026-82221 - Unauthenticated Reflected Cross-Site Scripting (XSS) in the WordPress RegistrationMagic plugin

CVE-2026-82221 was recently published, an unauthenticated XSS vulnerability I discovered in the WordPress RegistrationMagic plugin, affecting plugin versions <= 6.0.9.8. In this article, I intend to provide a detailed analysis of the vulnerability, including its root cause, potential impact, and its proof of concept.

> read more

articles: