Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
18 results
wp2shell-poc preview

wp2shell-poc

GitHubcolere-sys/wp2shell-poc

Analysis and end-to-end implementation of the patched wordpress RCE vulnerability - CVE-2026-60137 and CVE-2026-63030

ctfeducationexploit-frameworks+5
3
1 month ago
WP2Shell preview

WP2Shell

GitHubg0d150ne/wp2shell

Modular WordPress pre-auth exploit framework chaining SQL injection and authentication bypass to deliver remote code execution, interactive shells,…

exploitationexploit-frameworkspayload-development+7
23 days ago
vulnerable-bsr-lab-CVE-2023-6933 preview

vulnerable-bsr-lab-CVE-2023-6933

GitHubtrex96/vulnerable-bsr-lab-cve-2023-6933

Hands-on lab for CVE-2023-6933, a PHP Object Injection vulnerability in Better Search Replace WordPress plugin, with Docker deployment, nuclei…

educationexploit-frameworkslabs-practice+3
11 months ago
CVE-2024-6366 preview

CVE-2024-6366

GitHubabdurahmon3236/cve-2024-6366

Metasploit exploit module for CVE-2024-6366, an unauthenticated file upload remote code execution in WordPress User Profile Builder before 3.11.8,…

code-analysisexploit-frameworkspayload-development+3
2 years ago
CVE-2026-49083 preview

CVE-2026-49083

GitHubizxci/cve-2026-49083

Python exploit for CVE-2026-49083 targeting privilege escalation in the LatePoint Calendar Booking WordPress plugin. Provides automated exploitation…

exploitationexploit-frameworkspenetration-testing+3
2 months ago
CVE-2022-1329-WordPress-Elementor-3.6.0-3.6.1-3.6.2-Remote-Code-Execution-Exploit preview

CVE-2022-1329-WordPress-Elementor-3.6.0-3.6.1-3.6.2-Remote-Code-Execution-Exploit

GitHubakucybersec/cve-2022-1329-wordpress-elementor-3.6.0-3.6.1-3.6.2-remote-code-execution-exploit

Exploit for CVE-2022-1329, a WordPress Elementor plugin RCE vulnerability, allowing authenticated users to upload and execute arbitrary PHP files via…

exploit-frameworkspayload-developmentpenetration-testing+3
234 years ago
CVE-2025-3616 preview

CVE-2025-3616

GitHubb4d-53ct0r/cve-2025-3616

Metasploit module exploiting arbitrary file upload in Greenshift WordPress plugin (CVE-2025-3616) to achieve RCE via MIME spoofing, with…

authenticationexploit-frameworkspayload-development+3
7 months ago
nate158g-m-w-n-l-p-d-a-o-e preview

nate158g-m-w-n-l-p-d-a-o-e

GitHubnate0634034090/nate158g-m-w-n-l-p-d-a-o-e

### This module requires Metasploit: https://metasploit.com/download# Current source: https://github.com/rapid7/metasploit-framework##class…

exploit-frameworkspayload-generationpenetration-testing-frameworks+3
144 years ago
wordpress-exploit-framework preview
Archived

wordpress-exploit-framework

GitHubrastating/wordpress-exploit-framework

A Ruby framework designed to aid in the penetration testing of WordPress systems.

exploit-frameworkspayload-developmentpenetration-testing+3
1.0k6 years ago
WordPress_Backup_Migration-RCE_Unauthenticated preview

WordPress_Backup_Migration-RCE_Unauthenticated

GitHubjoaoaugustom/wordpress_backup_migration-rce_unauthenticated

This exploit is based on CVE-2023-6553 and was built upon the original exploit by Chocapik, it was added that a direct reverse shell can be obtained.

command-and-controlexploit-frameworkspayload-development+3
25 days ago
XAttacker preview

XAttacker

GitHubmoham3driahi/xattacker

X Attacker Tool ☣ Website Vulnerability Scanner & Auto Exploiter

exploit-frameworksinformation-gatheringpenetration-testing+2
1.8k2 years ago
killshot preview

killshot

GitHubbahaabdelwahed/killshot

A Penetration Testing Framework, Information gathering tool & Website Vulnerability Scanner

exploit-frameworksfuzzinginformation-gathering+6
7818 months ago
CVE-2021-24155.rb preview

CVE-2021-24155.rb

GitHub0dayninja/cve-2021-24155.rb

WordPress Backup Guard Authenticated Remote Code Execution Exploit

exploit-frameworkspayload-developmentpenetration-testing+3
105 years ago
CVE-2026-49083 preview

CVE-2026-49083

GitHub87achrafg-stack/cve-2026-49083

Python exploit for CVE-2026-49083, a privilege escalation vulnerability in the LatePoint Calendar Booking WordPress plugin, enabling unauthorized…

exploitationexploit-frameworkspenetration-testing+3
2 months ago
wordpress-CVE-2018-6389 preview

wordpress-CVE-2018-6389

GitHubdsfau/wordpress-cve-2018-6389

Metasploit module for WordPress DOS load-scripts.php CVE-2018-638

exploit-frameworkspenetration-testingvulnerability-analysis+1
28 years ago
-CVE-2024-31211 preview

-CVE-2024-31211

GitHubabdurahmon3236/-cve-2024-31211

Metasploit module that exploits a WordPress unserialization vulnerability (CVE-2024-31211) in WP_HTML_Token to achieve remote code execution.

code-analysisexploit-frameworkspayload-development+3
2 years ago
wp2shell-poc2 preview

wp2shell-poc2

GitHubattackercan/wp2shell-poc2

CVE-2026-63030

command-and-controlexploit-frameworkspayload-development+5
71 month ago
NekoBotV1 preview
Archived

NekoBotV1

GitHubtegal1337/nekobotv1

NekoBot | Auto Exploiter With 500+ Exploit 2000+ Shell

exploit-frameworkspenetration-testingred-teaming+2
3965 years ago