
TryHack3M-Bricks-Heist
🧱 CVE-2024-25600 WordPress Bricks Builder RCE Exploit + TryHackMe Bricks Heist CTF Write-up

🧱 CVE-2024-25600 WordPress Bricks Builder RCE Exploit + TryHackMe Bricks Heist CTF Write-up

Quick Review about the SQL-Injection in the NEX-Forms Plugin for WordPress

A collection of useful resources for hacking WordPress and it's plugins and themes

This is a recurrence of cve-2019-9787 on Wordpress and a hash-based defense.

CVE-2024-5326 Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.1.2 - Missing Authorization to Arbitrary Options Update

Identifies domains which run WordPress and tests against vulnerabilities (CVE-2023-32243) / #VU76395 / etc...

Automates exploitation of CVE-2021-29447 in WordPress media upload to extract files via XXE, generating payloads and running an HTTP server for…

Proof-of-concept exploit for CVE-2024-5326, a missing authorization vulnerability in the PostX WordPress plugin allowing authenticated attackers to…

Demonstration of the WP Visitor Statistics plugin exploit

Wordpress likes and dislikes add-on - SQL Injection

The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated…

Proof-of-concept exploit for CVE-2026-7665, an unauthenticated information disclosure in Essential Addons for Elementor, allowing extraction of…

Unauthenticated SQL Injection exploit for WordPress Likes and Dislikes Plugin ≤ 1.0.0

Exploit for CVE-2025-10294: authentication bypass via empty HMAC key in ownid_shared_secret, enabling JWT forgery and unauthorized WordPress admin…

Exploit for CVE-2021-29447, an XXE vulnerability in WordPress 5.7.0 and earlier. Generates malicious WAV payloads to read arbitrary server files via…

Proof-of-concept for Denial of Service (DoS) attacks against WordPress 4.9.8 and 5.5 via unauthenticated requests to vulnerable admin pages, causing…

WordPress Likes and Dislikes Plugin <= 1.0.0 is vulnerable to SQL Injection

Proof-of-concept scripts demonstrating reflected XSS in the Ultimate Classified Listings WordPress plugin and admin cookie theft via crafted payloads…