
wp2shell
wp2shell — WordPress Core Pre-Auth RCE (CVE-2026-63030 + CVE-2026-60137). Exploit toolkit + remediation.

wp2shell — WordPress Core Pre-Auth RCE (CVE-2026-63030 + CVE-2026-60137). Exploit toolkit + remediation.

CVE-2026-63030 / CVE-2026-60137 - WordPress pre-auth RCE scanner

Exploit PoC and root-cause analysis for a critical unauthenticated PHP object injection in WordPress Database for Contact Form 7, leading to RCE via…

Hands-on reproduction of CVE-2024-28000 in LiteSpeed Cache using an isolated WordPress lab. Includes reconnaissance, vulnerable hash recovery,…

Study and exploit the vulnerability CVE-2022-21661 that allows SQL Injections through plugins POST requests to WordPress versions below 5.8.3.

Detailed penetration test report demonstrating unauthenticated path traversal (CVE-2019-11447) in WordPress Simple Backup plugin, including…

Pre-auth RCE exploit for WordPress (CVE-2026-63030 + CVE-2026-60137) chaining route confusion and SQL injection into full shell access. Includes…

PoC exploit for CVE-2024-1813: PHP object injection in Simple Job Board WordPress plugin, achieving unauthenticated RCE via gadget chain. Includes…

Docker-based lab for reproducing CVE-2026-49060, an unauthenticated privilege escalation in the Hippoo Mobile App for WooCommerce WordPress plugin.…

WordPress unauthenticated RCE exploit combining route confusion and SQL injection. Automated script, lab setup, and detailed vulnerability analysis…

Docker-based vulnerable WordPress lab with Python exploit demonstrating pre-auth route confusion and SQL injection chain (CVE-2026-63030 +…

Proof-of-concept exploit for CVE-2015-9357: stored XSS in WordPress smiley parser that bypasses wp_kses, chains nonce forgery to create admin…

Proof-of-concept exploit for a WordPress plugin vote-limit bypass using spoofed X-Forwarded-For headers; ships a Docker lab to validate…

Docker-based lab for reproducing and validating CVE-2026-56011, an unauthenticated XSS vulnerability in MapPress Maps for WordPress, with vulnerable…

Exploit PoC for CVE-2016-10033 targeting WordPress 4.6 with Docker-based vulnerable container for reverse shell without authentication.

Demonstration of the SQL injection vulnerability in wordpress 5.8.2

CVE-2026-2576 — Business Directory Plugin SQLi PoC (Local Setup). Unauthenticated Time-Based Blind SQL Injection Business Directory Plugin for…

GoDAM WordPress plugin <= 1.12.2 unauthenticated file upload RCE (CVE-2026-14282)