Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
wordpress-hacking — A collection of useful resources for hacking WordPress and it's plugins and themes | Kitploit
Tools/GitHubGitHub/stealthcopter/wordpress-hacking
Vulnerability AnalysisDynamic Code Analysis (DAST)ExploitationWeb Application ExploitationWeb SecurityPenetration TestingCurated Resources
GitHubstealthcopter/wordpress-hacking

wordpress-hacking

A collection of useful resources for hacking WordPress and it's plugins and themes

View Repository
8995 months agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

WordPress Hacking

Some useful resources for hacking WordPress and it's plugins and themes.

Bug Bounty

If you're passionate about finding and reporting WordPress vulnerabilities, consider joining these bug bounty programs: Wordfence and Patchstack. Signing up through my Wordfence link gives me a small bonus when you report 5 vulns, helping support my work on tools and resources for the community. Thank you!

Plugin

I have written a plugin designed to help dynamic analysis and hacking of WordPress plugins and themes, this can be found in the plugin branch in this repo.

Reports

The reports directory contains a selection of my publicly disclosed vulnerability reports that were disclosed to bug bounty programs. I've tried to get a good cross-section of different vulnerability types.

CVEBountyVulnerability📄 Report 🐍 Python PoC 🔗 Blog
CVE-2024-3050911.25 AXPSellKit Subscriber+ Arbitrary File Download📄 🐍
CVE-2024-3242$469Brizy Contributor+ Arbitrary File Upload📄 🐍
CVE-2024-4361$325SiteOrigin Contributor+ XSS📄
CVE-2024-22144270 AXPGoTMLS Unauthenticated RCE📄 🐍 🔗
CVE-2024-6386$1639WPML Contributor+ SSTI to RCE📄 🔗
CVE-2024-4637$434Slider Revolution Contributor+ XSS📄 🐍
CVE-2024-5153$361Starlar Elementor Addons Arbitrary Folder Deletion📄 🐍

These 📄 reports are in their original formats when originally submitted. Any mistakes are mine, for prettier versions please see the ones that have linked blog posts 🔗. Where I created a Python proof-of-concept script you will find it in the folder or directly by clicking on 🐍.

Python Functions

Feel free to reuse my Python code to help write you own PoCs, in future I may turn some of the functions into an easy-to-use library.

Support

If you love what I'm doing with wordpress-hacking or my other projects, please feel free to contribute without spending money by creating issues, PRs, or just messaging me to let you know you use it. And of course, you can directly sponsor this project on GitHub or buy me a coffee ☕! Thank you for your support – it means the world to me and the open source community!

Download Tool
CVE-2024-5237660 AXPBoat Rental System Unauthenticated Arbitrary File Upload📄 🐍
CVE-2024-5047758.8 AXPStacks Mobile App Unauthenticated Privileged Escalation📄
CVE-2025-0366$782Jupiterx Core Contributor+ SVG to RCE📄 🐍 🔗