CVE•Published 2026-06-19•Modified 2026-06-22•1 article on news•4 live references•NVD data
CVE-2026-7515
Vulnerability data via NVD (ingested)
CVSS v3.1
9.8
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS percentile
—
Weaknesses (CWE)
Description
The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.
Timeline
Published 2026-06-19
Modified 2026-06-22
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
More intel sources (5)
Shodan report
vuln:CVE-2026-7515Country / ASN / product breakdown for the vuln query.
Censys
vulnerabilities.cve_id: CVE-2026-7515Censys host search filtered to this CVE id.
grep.app
CVE-2026-7515Public source-code mentions — fast PoC discovery.
GitHub code
CVE-2026-7515GitHub code search for direct mentions.
Google dork
"CVE-2026-7515" exploit -site:nvd.nist.govWrite-ups and news, NVD excluded.
Known PoCs on GitHub (8)
CVE-2026-75158 repos
nomi-sec/PoC-in-GitHubunknown
📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.
MihaiCiprianChezan/Agentic-First-Enterprisesunknown
A reference operating model for organizations where any role can be filled by a human or an agent, every process is built for agents first, and every flow can be paused, adjusted b…
daloyjs/daloyTypeScript
The first TypeScript REST API framework built for secure AI-assisted services. DaloyJS combines runtime portability, contract-first OpenAPI, generated typed clients, zero-dependenc…
hugefiver/mystarsunknown
nlip-project/security_guidelinesunknown
NLIP’s Security Guidelines and Best Practices is the companion to the NLIP core specification, brought to you by the NLIP Security Working Group.
phuclam1908/Cloud-API-Based-Network-Application-Security-for-Small-Company-ServicesHTML
blamejs/pkiJavaScript
Pure-JavaScript PKI toolkit that owns its stack — X.509, ASN.1/DER, CMS, PQC-first.
Polosss/By-Poloss..-..CVE-2026-7515-PoCunknown
Unauthenticated Local File Inclusion