
CVE-2024-9796
CVE-2024-9796 WP-Advanced-Search < 3.3.9.2 - Unauthenticated SQL Injection. Poc.

CVE-2024-9796 WP-Advanced-Search < 3.3.9.2 - Unauthenticated SQL Injection. Poc.

Unauthenticated time-based blind SQL injection exploit for NotificationX WordPress plugin (CVE-2024-1698) that extracts admin username and password…

Study and exploit the vulnerability CVE-2022-21661 that allows SQL Injections through plugins POST requests to WordPress versions below 5.8.3.

This repository contains a practical research and validation toolkit for CVE-2025-4396, an unauthenticated Time-Based Blind SQL Injection affecting…

Complete exploitation toolkit for CVE-2026-3180 - WordPress Contest Gallery SQL Injection vulnerability. Features automated data extraction, WAF…

CVE-2025-4396 - WordPress Relevanssi Time-Based Blind SQL Injection

Exploit for CVE-2025-2011

CVE-2026-63030 + CVE-2026-60137 - “wp2shell”: unauthenticated RCE in WordPress core


unauthenticated RCE in WordPress core (CVE-2026-63030 + CVE-2026-60137)

CVE-2022-0169 - WordPress Photo Gallery SQLi PoC

CVE-2026-63030 (RCE) + CVE-2026-60137 (SQLi)