Bug bounty writeups
Removing an Account Admin from a team only revokes the active session but fails to delete the persistent membership record, allowing the removed admin to regain full team access simply by logging back in.
A business logic flaw let an organization owner invite a teammate directly as an admin through the desktop client, completely skipping the pro-subscription check enforced on the web app.
Exploiting a critical WordPress misconfiguration where the default registration role was set to Administrator, granting any anonymous user full control over the entire WordPress instance.
Leveraging open WordPress user registration on a corporate subdomain to access internal media files through the WP REST API, exposing confidential corporate presentations and documents.