From the author
Articles by Md. Moniruzzaman Prodhan
Browse the author’s published research, guides, and practical insights.
CVE-2026-4431: Unauthenticated Post Modification Vulnerability in the Easy Post Submission WordPress Plugin
Easy Post Submission is a WordPress plugin that allows website admins to accept post submissions from the website’s frontend. It also supports guest post submissions, allowing users to submit posts without needing an acc...
CVE-2026-5348: Broken REST API Authorization Exposes Private Course Content in Academy LMS
Academy LMS is a WordPress learning managmeent system plugin. The plugin is not widely deployed in WordPress ecosystem but currently the plugin recorded 100k+ downloads and 2K active installations. So two thousands activ...
Decompiling and Rebuilding Android APKs for Penetration Testing
Android applications are commonly distributed as APK files. During penetration testing, these APKs can be unpacked and decompiled to analyze their internal components and source code. In many cases we may also need to mo...
Path Traversal in Otter Wiki 2.22.1 DataTable Embedding Leads to Local File Disclosure
Otter Wiki is an open-source, self-hosted wiki application built with Python and Flask. It uses Markdown for page content and stores wiki data in a Git repository. The project also supports features such as user authenti...
From Editor Role to Administrator Account Takeover: Anatomy of CVE-2026-9851 in a WordPress Plugin
Booking Package is a popular WordPress plugin designed for managing appointments, reservations, events, room rentals, and other types of online bookings directly from a WordPress website. Since its release, the plugin go...
CVE-2025-60790: How Unbounded ZIP Extraction Led to a Denial-of-Service Risk
ProcessWire is a free and open-source content management system built with PHP. Although it is not as widely used as WordPress, BuiltWith reports that more than 20,000 websites use ProcessWire, while W3Techs estimates th...
Official Download, Malicious File: The CPUID/CPU-Z Incident Explained
Responsible IT or security guys always recommend to download any software/package from official website/source. But what happens when that official website or source is compromised ? Yeah that happened with CPUID. In Apr...
kAIPTA Preparation Guide: What to Practice for the Exam
We’ve just launched kAIPTA (Certified AI Penetration Testing Associate), an associate-level certification focused entirely on AI application penetration testing. In this blog post, I’ll share some practical tips to help...
Phishing Attempts Targeting Our Support Inbox: What We Saw and How We Responded
At Knight Squad Academy, we provide support through multiple online channels, and our team actively maintains our support inbox. Recently, we noticed a few phishing attempts targeting that inbox. This is pretty common fo...
When “Paid” Becomes “Failed”: A Fluent Forms Payment Integrity Bug (CVE-2025-13748)
Modern WordPress sites frequently rely on third-party plugins to handle payments, orders, and other business-critical workflows. When these plugins process financial data, even small security oversights can have outsized...