
CVE-2025-7441
StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload

StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload

Schema & Structured Data for WP & AMP < 1.60 - Unauthenticated Arbitrary Media Upload [POC & Xploit]

PoC CVE-2026-8732 (WP Maps Pro <= 6.1.0)

Exploit for CVE-2020-9006 targeting WordPress Popup-Builder plugin via SQL injection and PHP deserialization, with payload generation and Nmap…

Unauthenticated 0-click RCE exploit for CVE-2024-50498. Exploits a code injection vulnerability in the LUBUS WP Query Console plugin to execute…

WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover

Proof of Concept for Stored-XSS on Vulnerable WP-Statistics Plugin known as CVE-2025-9816

Arbitrary File Upload in AI Bud – AI Content Generator, AI Chatbot, ChatGPT, Gemini, GPT-4o <= 1.8.4

StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload

Quentn WP <= 1.2.8 - Unauthenticated Privilege Escalation

Python exploit for CVE-2025-7340, an unauthenticated file upload vulnerability in the WordPress HT Contact Form widget, enabling remote code…

Exploit script for CVE-2024-50498 code injection in WordPress WP Query Console that checks vulnerability and delivers a reverse shell.

WP Query Console <= 1.0 - Unauthenticated Remote Code Execution

All-in-One WP Migration and Backup <= 7.86 - Authenticated (Administrator+) Arbitrary PHP Code Injection

This is POC for CVE-2024-2667 (InstaWP Connect – 1-click WP Staging & Migration <= 0.1.0.22 - Unauthenticated Arbitrary File Upload)

ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation

Python exploit for RCE in Wordpress

Exploit of the privilege escalation vulnerability of the WordPress plugin "WP GDPR Compliance" by "Van Ons"…