
XSS2Shell
Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…
command-and-controlexploitationinformation-gathering+6

Exploits WordPress pre-auth XSS (CVE-2026-64638) to achieve remote code execution, installing an AES-encrypted backdoor webshell with persistence,…

CVE-2026-3844 — Unauthenticated Arbitrary File Upload to RCE in Breeze Cache (WordPress). CVSS 9.8 CRITICAL. Mass scanner + auto shell injector with…

Gogs RCE via argument injection in git rebase (CWE-88) — Python PoC. CVE-2026-52806


WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover



Fully undetectable and evasive ransomware written in Rust, leveraging a BYOVD technique to disable AV/EDR solutions on the infected systems.