From the author
Articles by Md. Moniruzzaman Prodhan
Browse the author’s published research, guides, and practical insights.
Path Traversal in Otter Wiki 2.22.1 DataTable Embedding Leads to Local File Disclosure
Otter Wiki is an open-source, self-hosted wiki application built with Python and Flask. It uses Markdown for page content and stores wiki data in a Git repository. The project also supports features such as user authenti...
From Editor Role to Administrator Account Takeover: Anatomy of CVE-2026-9851 in a WordPress Plugin
Booking Package is a popular WordPress plugin designed for managing appointments, reservations, events, room rentals, and other types of online bookings directly from a WordPress website. Since its release, the plugin go...
CVE-2025-60790: How Unbounded ZIP Extraction Led to a Denial-of-Service Risk
ProcessWire is a free and open-source content management system built with PHP. Although it is not as widely used as WordPress, BuiltWith reports that more than 20,000 websites use ProcessWire, while W3Techs estimates th...
Official Download, Malicious File: The CPUID/CPU-Z Incident Explained
Responsible IT or security guys always recommend to download any software/package from official website/source. But what happens when that official website or source is compromised ? Yeah that happened with CPUID. In Apr...
kAIPTA Preparation Guide: What to Practice for the Exam
We’ve just launched kAIPTA (Certified AI Penetration Testing Associate), an associate-level certification focused entirely on AI application penetration testing. In this blog post, I’ll share some practical tips to help...
Phishing Attempts Targeting Our Support Inbox: What We Saw and How We Responded
At Knight Squad Academy, we provide support through multiple online channels, and our team actively maintains our support inbox. Recently, we noticed a few phishing attempts targeting that inbox. This is pretty common fo...
When “Paid” Becomes “Failed”: A Fluent Forms Payment Integrity Bug (CVE-2025-13748)
Modern WordPress sites frequently rely on third-party plugins to handle payments, orders, and other business-critical workflows. When these plugins process financial data, even small security oversights can have outsized...