
CVE-2024-10508
Proof-of-concept exploit for CVE-2024-10508: unauthenticated privilege escalation via password recovery bypass in RegistrationMagic WordPress plugin…

Proof-of-concept exploit for CVE-2024-10508: unauthenticated privilege escalation via password recovery bypass in RegistrationMagic WordPress plugin…

Python exploit for CVE-2019-14314: authenticated SQL injection in NextGEN Gallery 3.2.10 WordPress plugin, extracting password hashes from the…

Mass exploitation tool for CVE-2026-8206 – Unauthenticated Privilege Escalation via 'handle_forgot_password' in Kirki WordPress plugin (≤6.0.6).

Proof-of-concept for CVE-2023-37756: weak password requirements in i-doit Pro admin-center enabling brute-force login and malicious plugin upload…

Proof-of-concept exploit for CVE-2025-4334, a privilege escalation vulnerability in the Simple User Registration WordPress plugin (<= 6.3), allowing…

Proof-of-concept exploit for CVE-2026-5076 demonstrating unauthenticated admin account takeover in ARMember Premium via SQL injection and plaintext…


CVE-2023-5359 scanner for W3 Total Cache cleartext storage vulnerability. Detects exposed credentials (API keys, OAuth tokens) in publicly accessible…

LiteSpeed Cache Privilege Escalation PoC

LiteSpeed Cache Privilege Escalation PoC - CVE-2024-28000

Exploits unauthenticated privilege escalation in SMS Alert WooCommerce plugin (CVE-2026-11387) via OTP bypass and arbitrary password reset, with…

WordPress Simple Link Directory Plugin < 14.8.1 is vulnerable to a high priority Broken Authentication

TeamCity IntelliJ IDEA Plugin Credential Interception

CVE-2025-4094 – WordPress Digits Plugin < 8.4.6.1 - OTP Authentication Bypass

Remotely test password strength of WordPress bloging software

ARMember Premium <= 7.3.1 Full Admin Account Takeover

Unauthenticated Privilege Escalation to Administrator via Role Form Field

CVE-2025-2539 - WordPress File Away <= 3.9.9.0.1 - Arbitrary File Read