
CVE-2024-5326-Poc
Proof-of-concept exploit for CVE-2024-5326, a missing authorization vulnerability in the PostX WordPress plugin allowing authenticated attackers to…

Proof-of-concept exploit for CVE-2024-5326, a missing authorization vulnerability in the PostX WordPress plugin allowing authenticated attackers to…

Exploit for CVE-2025-10294: authentication bypass via empty HMAC key in ownid_shared_secret, enabling JWT forgery and unauthorized WordPress admin…

Brute Force Wordpress Blogs.

Custom Content Types and Fields plugin for WordPress

Exploit PoC for unauthenticated doctor/receptionist account creation in the KiviCare WordPress plugin via improper privilege management, providing…

AdForest <= 6.0.9 - Authentication Bypass to Admin

Wordpress REST API | Custom API Generator For Cross Platform And Import Export In WP 1.0.0 - 2.0.3 - Missing Authorization to Unauthenticated…

SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter

PoC exploit for CVE-2026-2991 — authentication bypass in KiviCare WordPress plugin (≤4.1.2) allowing unauthenticated patient account takeover and…

A security-hardened fork of the abandoned "PostGallery" WordPress plugin. Fixes critical Arbitrary File Upload (CVE-2025-13543) and Guest Access…

Exploit for CVE-2026-8206 targeting unauthenticated account takeover in the Kirki WordPress plugin. Provides a proof-of-concept for security testing…

CVE-2021-34646 PoC

Automated auth bypass exploit for CVE-2025-0316 targeting WordPress WP Directorybox Manager. Features user enumeration, proxy support,…

Temporary WordPress plugin requiring authentication for the Core REST Batch API endpoint to mitigate the wp2shell vulnerability chain…

Wechat Social login <= 1.3.0 - Authentication Bypass

JAY Login & Register <= 2.4.01 - Authentication Bypass via Cookie

Proof-of-concept exploit for CVE-2026-8181, an authentication bypass in the Burst Statistics WordPress plugin. Demonstrates remote, unauthenticated…

CVE-2025-60188 Atarim Plugin Exploit