
wp2shell
PoC for CVE-2026-63030 + CVE-2026-60137, AKA WP2Shell

PoC for CVE-2026-63030 + CVE-2026-60137, AKA WP2Shell

A static code analysis for WordPress (and PHP)

WordPress REST API SQLi to RCE PoC (CVE-2026-63030 & CVE-2026-60137)

PoC for CVE-2024-1512 in MasterStudy LMS WordPress Plugin.

Post Saint <= 1.3.1 plugin for WordPress Arbitrary File Upload

Educational PoC + lab for CVE-2026-63030 + CVE-2026-60137: pre-auth SQLi in WordPress core via REST batch-route confusion

CVE-2026-63030, CVE-2026-60137, wp2shell scanner

Validation target: minimal WordPress core slice reproducing the wp2shell (CVE-2026-63030 + CVE-2026-60137) REST-to-SQLi chain

Metasploit exploit module for CVE-2024-6366, an unauthenticated file upload remote code execution in WordPress User Profile Builder before 3.11.8,…

CVE-2026-63030: WordPress REST batch-endpoint array desync. Mechanism, detection, mitigation, and a safe reproduction lab.

WordPress wp2shell pre-auth RCE exploit kit (CVE-2026-63030 + CVE-2026-60137)

S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator <= 1.7.7 - Authenticated (Editor+) Arbitrary File Upload

Proof-of-concept exploit for CVE-2023-4634, a remote code execution vulnerability in the WordPress Media Library Assistant plugin. Includes a…

Unauthenticated Remote Code Execution (RCE) in WordPress Core allows attackers to execute arbitrary code without logging in by chaining…

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

Static code analysis scanner for WordPress plugins and themes. Detects vulnerabilities like XSS and SQL injection via modular, extensible…

A security-hardened fork of "Simply Show Hooks". Replaces the compromised original (CVE-2024-6297) and patches unlisted Cross-Site Scripting (XSS)…

WordPress Passster Plugin <= 4.2.18 is vulnerable to Cross Site Scripting (XSS)