
CVE-2024-1247-PoC
Post Saint <= 1.3.1 plugin for WordPress Arbitrary File Upload

Post Saint <= 1.3.1 plugin for WordPress Arbitrary File Upload

Radare2 AI plugin using local or remote LLMs for decompilation, function explanation, vulnerability detection, renaming, and scripted reverse…

(CVE-2024-51793) Wordpress Plugin: Computer Repair Shop <= 3.8115 - Unauthenticated Arbitrary File Upload

CVE-2022-1329 exploit for WordPress Elementor plugin (3.6.0-3.6.2) enabling authenticated remote code execution via missing capability check and…

Python exploit script for CVE-2025-2294, an unauthenticated Local File Inclusion vulnerability in WordPress Kubio AI Page Builder ≤ 2.5.1. Supports…

realtime cross-tool collaborative reverse engineering

All-in-One WP Migration and Backup <= 7.86 - Authenticated (Administrator+) Arbitrary PHP Code Injection

WooCommerce Designer Pro 1.9.26 - Arbitrary File Upload

Partners <= 0.2.0 - Unauthenticated PHP Object Injection

VRPConnector <= 2.0.1 - Unauthenticated PHP Object Injection

DS.DownloadList <= 1.3 - Unauthenticated PHP Object Injection

CVE-2026-2002 writeup and Proof-of-concept

Introduction to CVE-2023-6933 Vulnerability

Proof-of-Concept script for WordPress plugin Bit File Manager version 6.0 - 6.5.5 Unauthenticated Remote Code Execution via Race Condition…

CVE-2025-3914-PoC | The Aeropage Sync for Airtable WordPress plugin (≤ v3.2.0) is vulnerable to authenticated arbitrary file uploads due to…

PoC for CVE-2026-3891 — Unauthenticated Arbitrary File Upload leading to Remote Code Execution in Pix for WooCommerce <= 1.5.0

Disclosure for CVE-2025-13339

Disclosure for CVE-2025-13156