Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Exploits — The whole collection of Exploits developed by me (Hacker5preme) | Kitploit
Tools/GitHubGitHub/hacker5preme/exploits
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed Teaming
GitHubhacker5preme/exploits

Exploits

The whole collection of Exploits developed by me (Hacker5preme)

View Repository
1072974 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Exploits

Collection of Exploits developed by Ron Jost

For Exploit-development requests, please reach out to me: [email protected]

Table of Contents:

  • Wordpress Plugin XCloner 4.2.12 - Remote Code Execution (Authenticated): CVE-2020-35948
  • Wordpress Plugin Modern Events Calendar Lite < 5.16.5 - RCE (Authenticated): CVE-2021-24145
  • Wordpress Plugin Modern Events Calendar Lite < 5.16.5 - Export Event Data (Unauthenticated): CVE-2021-24146
  • Wordpress Plugin Backup Guard < 1.6.0 - Remote Code Execution(Authenticated): CVE-2021-24155
  • Wordpress Plugin Responsive Menu < 4.0.3 - Remote Code Execution (Authenticated): CVE-2021-24160
  • Wordpress Plugin SP Project & Document Manager 4.21 - Remote Code Execution (Authenticated): CVE-2021-24347
  • Wordpress Plugin BulletProof Security V 5.1 - Sensitive information disclosure CVE-2021-39327
  • Wordpress Plugin Secure File Manager V <= 2.9.3 - Remtoe Code Execution (Authenticated): SFM-0day
  • Wordpress Plugin Duplcate Post V <= 1.1.9 - SQL Injection: CVE-2021-43408
  • Wordpress Plugin Catch Themes Demo Import V 1.6.1 - Remote Code Execution (Authenticated): CVE-2021-39352
  • Wordpress Plugin WP Visitor Statistics V <= 4.7 - SQL Injection (Authenticated): CVE-2021-24750
  • Wordpress Plugin RegistrationMagic V <= 5.0.1.5 - SQL Injection (Authenticated): CVE-2021-24862
  • Wordpress Plugin Modern Events Calendar V < 6.1.5 - SQL Injection (Unauthenticated) CVE-2021-24946
  • Wordpress Plugin Download Monitor WordPress V < 4.4.5 - SQL Injection (Authenticated) CVE-2021-24786
  • Wordpress Plugin 404 to 301 <= 2.0.2 - SQL-Injection (Authenticated) CVE-2015-9323
  • Wordpress Plugin Secure Copy Content Protection and Content Locking < 2.8.2 - SQL-Injection (Unauthenticated) CVE-2021-24931
  • Wordpress Plugin Perfect Survey < 1.5.2 - SQL Injection (Unauthenticated) CVE-2021-24762
  • Wordpress Plugin WP User Frontend < 3.5.26 - SQL-Injection (Authenticated)
  • GetSimple CMS 3.3.4 - Information Disclosure: CVE-2014-8722
  • OpenEMR 5.0.0 - Remote Code Execution (Authenticated): CVE-2017-9380
  • OpenEMR < 5.0.1.4 - Remote Code Execution (Authenticated): CVE-2018-15139
  • OpenEMR < 5.0.1.4 - /portal/account/register.php Authentication bypass: CVE-2018-15152
  • OpenEMR < 5.0.2 - Path Traversal (Authenticated): CVE-2019-14530
  • Trixbox 2.8.0.4 - 'lang' Remote Code Execution (Unauthenticated): CVE-2017-14535
  • Trixbox 2.8.0.4 - 'lang' Path Traversal: CVE-2017-14537
  • Monstra CMS <= 3.0.4 - Remote Code Execution (Authenticated): CVE-2018-6383
  • Codiad 2.8.4 - Remote Code Execution (Authenticated): CVE-2018-19423
  • Codiad 2.8.4 - Remote Code Execution (Authenticated) (2): CVE-2019-19208
  • Pluck CMS 4.7.13 - File Upload Remote Code Execution (Authenticated): CVE-2020-29607

CVE-2020-35948-Exploit

Exploit Title: Wordpress Plugin XCloner < 5.1.13 - Remote Code Execution (Authenticated)

CVE description:

An issue was discovered in the XCloner Backup and Restore plugin before 4.2.13 for WordPress. It gave authenticated attackers the ability to modify arbitrary files, including PHP files. Doing so would allow an attacker to achieve remote code execution. The xcloner_restore.php write_file_action could overwrite wp-config.php, for example. Alternatively, an attacker could create an exploit chain to obtain a database dump.

  • https://nvd.nist.gov/vuln/detail/CVE-2020-35948

ExploitDB:

  • https://www.exploit-db.com/exploits/50077

Exploit Description:

  • Vendor Homepage: https://www.xcloner.com/
  • Software Link: https://downloads.wordpress.org/plugin/xcloner-backup-and-restore.4.2.12.zip
  • Version: 4.2.1 - 4.2.12
  • Tested on Ubuntu 18.04

Usage:

image

Usage Example:

image

CVE-2021-24145-Exploit

Exploit Title: Wordpress Plugin Modern Events Calendar Lite < 5.16.5 - Remote Code Execution (Authenticated)

CVE description:

Arbitrary file upload in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly check the imported file, allowing PHP ones to be uploaded by administrator by using the 'text/csv' content-type in the request.

  • https://nvd.nist.gov/vuln/detail/CVE-2021-24145

ExploitDB:

  • https://www.exploit-db.com/exploits/50082

Exploit Description:

  • Vendor Homepage: https://webnus.net/modern-events-calendar/
  • Software Link: https://downloads.wordpress.org/plugin/modern-events-calendar-lite.5.16.2.zip
  • Version: Prior to 6.15.5
  • Tested on Ubuntu 18.04

Usage:

grafik

Usage Example:

grafik grafik

CVE-2021-24146-Exploit

Exploit Title: Wordpress Plugin Modern Events Calendar Lite < 5.16.5 - Export Event Data (Unauthenticated)

CVE description:

Lack of authorisation checks in the Modern Events Calendar Lite WordPress plugin, versions before 5.16.5, did not properly restrict access to the export files, allowing unauthenticated users to exports all events data in CSV or XML format for example.

  • https://nvd.nist.gov/vuln/detail/CVE-2021-24146

ExploitDB:

  • https://www.exploit-db.com/exploits/50084

Exploit Description:

  • Vendor Homepage: https://webnus.net/modern-events-calendar/
  • Software Link: https://downloads.wordpress.org/plugin/modern-events-calendar-lite.5.16.2.zip
  • Version: Prior to 6.15.5
  • Tested on Ubuntu 18.04

Usage:

grafik

Usage Example:

grafik

CVE-2021-24155-Exploit

Wordpress Plugin Backup Guard < 1.6.0 - Remote Code Execution (Authenticated)

CVE description:

The WordPress Backup and Migrate Plugin – Backup Guard WordPress plugin before 1.6.0 did not ensure that the imported files are of the SGBP format and extension, allowing high privilege users (admin+) to upload arbitrary files, including PHP ones, leading to RCE.

  • https://nvd.nist.gov/vuln/detail/CVE-2021-24155

ExploitDB:

  • https://www.exploit-db.com/exploits/50093

Exploit Description:

  • Vendor Homepage: https://backup-guard.com/products/backup-wordpress
  • Software Link: https://downloads.wordpress.org/plugin/backup.1.5.8.zip
  • Version: Prior to 1.6.0
  • Tested on Ubuntu 18.04

Usage:

grafik

Download Tool