Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
84 results
wpbullet preview

wpbullet

GitHubwebarx-security/wpbullet

A static code analysis for WordPress (and PHP)

code-analysisstatic-code-analysisvulnerability-analysis+1
240
7 years ago
comission preview

comission

GitHubintrinsec/comission

White-box CMS security scanner that audits core, plugin, and theme versions, detects unauthorized modifications, and cross-references known…

code-analysisconfiguration-auditingvulnerability-scanners+1
686 years ago
wpBullet preview

wpBullet

GitHubowasp/wpbullet

Static code analysis scanner for WordPress plugins and themes. Detects vulnerabilities like XSS and SQL injection via modular, extensible…

code-analysispenetration-testingstatic-code-analysis+3
624 years ago
wp2shell preview

wp2shell

GitHubcrypto-cat/wp2shell

PoC for CVE-2026-63030 + CVE-2026-60137, AKA WP2Shell

code-analysiseducationexploitation+2
31 month ago
CVE-2025-49029 preview

CVE-2025-49029

GitHubnxploited/cve-2025-49029

WordPress Custom Login And Signup Widget Plugin <= 1.0 is vulnerable to Arbitrary Code Execution

code-analysiseducationexploitation+3
21 year ago
CVE-2023-4634-PoC preview

CVE-2023-4634-PoC

GitHubevillm/cve-2023-4634-poc

Proof-of-concept exploit for CVE-2023-4634, a remote code execution vulnerability in the WordPress Media Library Assistant plugin. Includes a…

code-analysisexploitationpenetration-testing+3
7 months ago
WSS preview

WSS

GitHubnu11secur1ty/wss

Black-box WordPress vulnerability scanner that detects security issues, enumerates users, brute-forces logins via XMLRPC, and performs static PHP…

code-analysisinformation-gatheringpassword-attacks+3
32 months ago
CVE-2026-13157 preview

CVE-2026-13157

GitHubminhhk68/cve-2026-13157

Proof of concept and root-cause analysis for an authenticated arbitrary file upload in WordPress Theme Demo Import leading to remote code execution…

code-analysisexploitationpayload-development+4
1 month ago
rcno-reviews preview

rcno-reviews

GitHubsudotom/rcno-reviews

Recencio Book Reviews - WordPress plugin for managing book reviews. Originally created by Kemory Grubb. Security-patched fork resolving…

code-analysiscurated-resourceseducation+3
16 months ago
CVE-2025-2294 preview

CVE-2025-2294

GitHubr0otk3r/cve-2025-2294

Python exploit script for CVE-2025-2294, an unauthenticated Local File Inclusion vulnerability in WordPress Kubio AI Page Builder ≤ 2.5.1. Supports…

code-analysisexploitationinformation-gathering+3
1 year ago
CVE-2019-17234b-Exploit preview

CVE-2019-17234b-Exploit

GitHubadministra1tor/cve-2019-17234b-exploit

Wordpress IgniteUp plugin < 3.4.1 allows unauthenticated users to arbitrarily delete files on the webserver possibly causing DoS.

code-analysisexploitationpenetration-testing+2
5 years ago
wp2shell-scanner preview

wp2shell-scanner

GitHubzephrfish/wp2shell-scanner

CVE-2026-63030, CVE-2026-60137, wp2shell scanner

code-analysisexploitationinformation-gathering+5
581 month ago
CVE-2025-13595 preview

CVE-2025-13595

GitHubd0n601/cve-2025-13595

CIBELES AI <= 1.10.8 - Unauthenticated Arbitrary File Upload

code-analysisexploitationpayload-generation+3
19 months ago
CVE-2026-64638 preview

CVE-2026-64638

GitHubdungsocool/cve-2026-64638

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

code-analysisexploitationpayload-development+4
25 days ago
CVE-2026-49085 preview

CVE-2026-49085

GitHubizxci/cve-2026-49085

PHP Object Injection exploit for WP Insightly (CVE-2026-49085). Provides proof-of-concept code to demonstrate and test the vulnerability in affected…

code-analysisexploitationpenetration-testing+2
2 months ago
EXPLOIT-CVE-2026-8832 preview

EXPLOIT-CVE-2026-8832

GitHubfunixone/exploit-cve-2026-8832

Automated RCE exploit for WordPress WPCode Lite v2.3.5 (CVE-2026-8832) with 8 built-in PHP payloads, XML-RPC bypass, and web-based interactive shell…

code-analysisexploitationpayload-development+5
13 months ago
CVE-2026-3891-Pix-for-WooCommerce-Plugin-Exploit preview

CVE-2026-3891-Pix-for-WooCommerce-Plugin-Exploit

GitHubm4sh-wacker/cve-2026-3891-pix-for-woocommerce-plugin-exploit

PoC for CVE-2026-3891 — Unauthenticated Arbitrary File Upload leading to Remote Code Execution in Pix for WooCommerce <= 1.5.0

code-analysisexploitationpenetration-testing+2
211 month ago
WordPress_4.9.8_RCE_POC preview

WordPress_4.9.8_RCE_POC

GitHubbrianwrf/wordpress_4.9.8_rce_poc

A simple PoC for WordPress RCE (author priviledge), refer to CVE-2019-8942 and CVE-2019-8943.

code-analysisexploitationpayload-development+3
737 years ago
Previous12345Next