Blog
Things I write (sometimes with the help of AI 🤖)
2026
- CVE-2026-8679: AudioIgniter IDOR Exposes Private Playlist Data (CVSS 7.5)
- CVE-2026-9011: Ditty Plugin Exposes Non-Public Content to Anyone (CVSS 7.5)
- CVE-2026-8719: AI Engine Privilege Escalation via MCP OAuth (CVSS 8.8)
- CVE-2026-6403: Unauthenticated File Read in Quick Playground (CVSS 7.5)
- CVE-2026-5229: Form Notify Auth Bypass via LINE OAuth Callback (CVSS 9.8)
- CVE-2026-4094: FOX Currency Switcher Config Deletion (CVSS 8.1)
- CVE-2026-3718: ManageWP Worker Unauthenticated Stored XSS (CVSS 7.2)
- CVE-2026-6271: Unauthenticated RCE in Career Section Plugin (CVSS 9.8)
- CVE-2026-8181: Auth Bypass to Admin Takeover in Burst Statistics Plugin (CVSS 9.8)
- CVE-2026-3892: Motors Plugin Arbitrary File Deletion (CVSS 8.1)
- CVE-2026-5395: Fluent Forms <= 6.2.0 IDOR Exposes Form Entries (CVSS 8.2)
- CVE-2026-7330: Stored XSS in Auto Affiliate Links Plugin
- CVE-2026-6929: JoomSport Unauthenticated SQL Injection (CVSS 7.5)
- CVE-2026-5396: Fluent Forms Authorization Bypass via form_id (CVSS 8.2)
- CVE-2026-42668: Omnisend WooCommerce Account Takeover (CVSS 7.5)
- CVE-2026-4029: Unauthenticated DB Export in WP Database Backup (CVSS 7.5)
- CVE-2026-6320: Arbitrary File Read in Salon Booking System
- CVE-2026-5324: Unauthenticated XSS in Brizy Page Builder
- CVE-2026-5063: Stored XSS in NEX-Forms via Form Submission
- CVE-2026-4019: Unauthenticated Private Post Content Disclosure In Complianz Plugin
- CVE-2026-31431: Copy Fail — A Decade-Old Linux Kernel Privilege Escalation
- CVE-2026-6741: Critical Privilege Escalation in LatePoint Plugin (CVSS 8.8)
- CVE-2026-5364: Unauthenticated Arbitrary PHP Upload in CF7 Drag and Drop Plugin
- CVE-2026-6393: Authenticated Missing Authorization in BetterDocs Plugin
- CVE-2026-5428: Authenticated Stored XSS in Royal Elementor Addons Plugin
- Mailpit: Capture & Inspect Emails Locally for WordPress, Laravel, and PHP
- CVE-2026-3844: Unauthenticated Arbitrary File Upload To RCE in Breeze Cache Plugin (CVSS 9.8)
- CVE-2026-4388: Unauthenticated Stored XSS in Form Maker by 10Web Plugin
- AI Writes the Code Now. What Happens To QA?
- CVE-2026-5718: Unauthenticated File Upload To RCE in DnD Upload CF7 Plugin
- CVE-2026-2262: Easy Appointments Data Exposure via REST API
- CVE-2026-5478: Path Traversal File Read in Everest Forms
- CVE-2025-14868: CSRF File Deletion in Career Section Plugin
- CVE-2026-2834: Unauthenticated Stored XSS in Token of Trust Plugin
- CVE-2026-4365: Arbitrary Quiz Answer Deletion in LearnPress (CVSS 9.1)
- CVE-2026-5231: Stored XSS via utm_source in WP Statistics
- CVE-2026-4880: Barcode Scanner Plugin Privilege Escalation
- CVE-2026-3017: PHP Object Injection in Smart Post Show
- CVE-2025-15027: Privilege Escalation in JAY Login & Register (CVSS 9.8)
- CVE-2025-68043: Missing Authorization in LottieFiles Plugin (CVSS 9.8)
- CVE-2026-3124: Download Monitor Unauthenticated IDOR To Order Theft
- CVE-2026-3360: Tutor LMS Unauthenticated Billing Overwrite (CVSS 7.5)
- CVE-2026-3296: PHP Object Injection in Everest Forms (CVSS 9.8)
- CVE-2026-2942: Arbitrary File Upload in ProSolution WP Client
- CVE-2026-4003: CVSS 9.8 Privilege Escalation in Users Manager PN
- CVE-2025-15488: Unauthenticated Code Injection in Responsive Plus
- Cloudinary AI Skill for SQA: Auto-Upload Screenshots Explained
- CVE-2026-1233: Hardcoded MySQL Credentials in TTS Plugin
- axios Supply Chain Attack: Malicious Versions Deploy a RAT
- CVE-2026-5130: Debugger & Troubleshooter Unauthenticated Account Takeover
- Hello, World
- CVE-2026-4267: Unauthenticated Reflected XSS in Query Monitor Plugin
- CVE-2026-4257: SSTI to RCE in Contact Form by Supsystic
- CVE-2026-4987: Unauthenticated Payment Bypass in SureForms
- CVE-2026-3584: Kali Forms Unauthenticated RCE & Admin Takeover
- CVE-2026-1357: Unauthenticated RCE in WPvivid Backup Plugin (CVSS 9.8)
- CVE-2026-27384: Unauthenticated RCE in W3 Total Cache
- কীভাবে ভোট জালিয়াতি করবেন?
- Zikr When Waking Up - ঘুম থেকে জেগে উঠার সময়ের যিক্রসমূহ
- The Excellence of Zikr - যিক্রের ফযীলত
- সূরা আলে ইমরানের শিক্ষাসমূহ
- What Is WCAG? Web Accessibility Guidelines Explained
- CVE-2026-23550: CVSS 10 Privilege Escalation in Modular DS
- How Much Can Your Kid Earn? Financial Lessons for Parents
- A Tester's Guide to Letter Cases
- What Is Stochasticity? A Plain-English Explanation
- Personal Domain as Digital Ownership: Why It Matters
- WordPress Action and Filter Hooks: A Developer's Guide
- Custom Winter Theme for Disabled Sites on xCloud [Tutorial]
- যখন আল্লাহ কাউকে ভালবাসেন
2025
- 7 Software Testing Principles Every SQA Engineer Should Know
- SQA Career in WordPress: A Complete Ecosystem Guide
- SQA & DevOps Job Circulars: Updated Collection [2026]
- ISTQB Certification Journey: Tech X Webinar Full Recap
- The Muslim Creator’s Guide to Ethical AI Image Generation
- Essential RSS Feeds for QA & DevOps Engineers [2026]
- Free SMTP Options for SQA & Automation Engineers [2026]
- What Is WordPress? A Complete Beginner's Guide [2026]
- CVE-2025-12352: Arbitrary File Upload in Gravity Forms
- CVE-2025-12493: Local PHP File Inclusion in ShopLentor
- CVE-2025-11749: Privilege Escalation in AI Engine Plugin
- CVE-2025-13597: Arbitrary File Upload in AI Feeds Plugin
- FileMock for SQA Engineers: File Upload Testing Made Easy
- Smart Job Application Strategies for SQA Engineers
- CVE-2025-11457: Privilege Escalation in EasyCommerce Plugin
- BAQC Volunteer Formation Meeting: Notes & Key Decisions
- সন্তানের মৃত্যু কীভাবে মেনে নেবো?
- What Is Sanity Testing? A Beginner’s Friendly Guide
- BAQC SQA Community Meetup: Key Highlights & Takeaways
- কমেন্ট করার আগে ভাবুন - রেজ বেইট কিনা
- WPDeveloper SQA Job Circulars: Previous Openings Archive
- WordPress Bug Bounty: Best Resources for Security Researchers
- 3 Powerful AI Prompts for WordPress SQA Engineers
- 3 AI Prompts Every SQA Tester Should Use in 2026
- CSS Combinators Explained: Types, Syntax & Use Cases
- প্রাইস কত? ইনবক্স চেক করুন!
- The Soviet Mapmaker’s Secret: Why Post-USSR Peace Failed
- রাশিয়ার ইতিহাস
- লোকমান হাকিমের পরিচয়
- CVE-2025-49844: RediShell Redis Lua Sandbox Escape Explained
- শিশুর সংশোধন - প্রশংসা ও উপদেশ
- দুঃখ ও মুসিবতে ধৈর্যধারণ
- আমাকে জিজ্ঞেস করা কমন কিছু প্রশ্নের উত্তর
- CVE-2025-58246: My Contribution to WordPress 6.8.3 Security
- সন্তানকে তার উপযোগী কাজ দেওয়া আবশ্যক
- বিধর্মীদের উৎসব সংক্রান্ত কিছু প্রশ্নোত্তর
- দাওয়াত, দুআ ও কাচ্চি
- তুমি কি এমন সময় ঘুমাচ্ছ যখন রিজিক বণ্টন করা হচ্ছে?
- শিশুর মৃত্যুতে রাসুলুল্লাহ (সা:) কাঁদতেন এবং শিশুর পরিবারকে সমবেদনা জানাতেন
- Social Media Giveaways in Islam: Are They Permissible?
- Cloudflare Outage: How a React Bug Caused a Thundering Herd
- tag_escape() in WordPress: Secure HTML Escaping Guide
- দুআ তে শব্দচয়ন কেন জরুরি
- Bun Install Deep Dive: Speed & Optimization Secrets
- Atomic Habits: Walk Slowly, But Never Backward
- বাংলাদেশের মেডিক্যাল ও সরকারি সেবায় ডেটা সিকিউরিটির ভয়াবহ চিত্র
- What Is PHP SAPI? A Complete Beginner's Guide [2026]
- আধুনিক পরিবারের সংকট - ইসলামী সমাধান
- Linux seq Command Explained with Examples for Beginners
- Best Articles of September 2025: Monthly Reading Picks
- Binary Search in Practice: Finding Hikmah's User Count
- CVE-2025-58196: XSS in WordPress UiCore Elements Plugin
- CVE-2025-55715: Sensitive Info Exposure Affecting 300K+ Sites
- CVE-2025-54708: Stored XSS in WordPress B-Blocks Plugin
- Escaping vs. Sanitization in WordPress: A Developer’s Guide
- WordPress Security: My July 2025 CVE Contribution Recap
- Vibium - টেস্ট অটোমেশনের নতুন টুল?
- Masjid Fundraising: How to Give Sadaqah Jariyah
- Hetzner Cloud VPS: Why It's a Game Changer for Developers
- Check WordPress Plugin Compatibility with wp-since on xCloud
- 10 Common WordPress Mistakes to Avoid (Beginner’s FAQ Guide)
- php.ini Configuration for Nginx and OpenLiteSpeed [Guide]
- What Is SSH? Beginner's Guide to Secure Shell Protocol
- GoAccess Setup Guide for xCloud: Real-Time Web Analytics
- Markdown Cheat Sheet: Quick Reference for All Syntax
- প্রকৃত মুমিনের পাঁচটি গুণ