
TryHack3M-Bricks-Heist
🧱 CVE-2024-25600 WordPress Bricks Builder RCE Exploit + TryHackMe Bricks Heist CTF Write-up

🧱 CVE-2024-25600 WordPress Bricks Builder RCE Exploit + TryHackMe Bricks Heist CTF Write-up

The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated…

Proof-of-concept exploit for CVE-2026-7665, an unauthenticated information disclosure in Essential Addons for Elementor, allowing extraction of…

Unauthenticated SQL Injection exploit for WordPress Likes and Dislikes Plugin ≤ 1.0.0

Exploit for CVE-2021-29447, an XXE vulnerability in WordPress 5.7.0 and earlier. Generates malicious WAV payloads to read arbitrary server files via…

WordPress Likes and Dislikes Plugin <= 1.0.0 is vulnerable to SQL Injection

Go-based exploit for CVE-2021-29447 targeting WordPress 5.6.2 with PHP 8. Generates a malicious .wav payload to retrieve arbitrary files from the…

Proof-of-concept exploit for CVE-2025-47445, a path traversal vulnerability in the WordPress Eventin plugin. Includes setup instructions for a local…

PoC for CVE-2021-29447

PoC for CVE-2026-63030 + CVE-2026-60137, AKA WP2Shell

CVE-2024-9796 WP-Advanced-Search < 3.3.9.2 - Unauthenticated SQL Injection. Poc.

CVE-2026-9848 is an Unauthenticated SQL Injection (SQLi) vulnerability affecting the WP Ticket (Customer Support Ticket System & Helpdesk) plugin for…

This is an exploit script to find out wordpress admin's username and password hash by exploiting CVE-2024-1698.

Docker-based lab for reproducing and validating CVE-2026-56011, an unauthenticated XSS vulnerability in MapPress Maps for WordPress, with vulnerable…

WordPress Custom Login And Signup Widget Plugin <= 1.0 is vulnerable to Arbitrary Code Execution

WordPress Frontend Login and Registration Blocks Plugin <= 1.0.7 is vulnerable to Privilege Escalation

PoC exploit for CVE-2023-5561 that enumerates WordPress user email addresses via the /wp-json/wp/v2/users API endpoint. For authorized security…

Local Docker lab demonstrating CVE-2026-5718 arbitrary file upload in a WordPress plugin, with vulnerable and patched services for side-by-side…