
CVE-2021-29447-POC
Automates exploitation of CVE-2021-29447 in WordPress media upload to extract files via XXE, generating payloads and running an HTTP server for…

Automates exploitation of CVE-2021-29447 in WordPress media upload to extract files via XXE, generating payloads and running an HTTP server for…

The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated…

Exploit for CVE-2025-10294: authentication bypass via empty HMAC key in ownid_shared_secret, enabling JWT forgery and unauthorized WordPress admin…

Wordpress Plugin Canto < 3.0.5 - Remote File Inclusion (RFI) and Remote Code Execution (RCE)

Royal Elementor Addons - Unauthenticated Remote Code Execution

CVE-2023-29384 Auto Exploiter on WordPress Job Board and Recruitment Plugin

PoC exploit chain for WordPress pre-auth XSS to RCE via DOM clobbering, REST JSONP/SOME, and plugin upload, with Docker lab verification and…

WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover

The BerqWP – Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is…

WordPress wp2shell vulnerability-chain scanner for CVE-2026-63030 and CVE-2026-60137, with active detection, optional PoC, JSON export.

CIBELES AI <= 1.10.8 - Unauthenticated Arbitrary File Upload

Exploit tool for SportsPress Plugin LFI & RCE (CVE-2025-15368) - Proof of Concept

AI Feeds <= 1.0.11 - Unauthenticated Arbitrary File Upload

Exploit scripts and scanner for CVE-2024-27956, a WordPress plugin vulnerability, including a modified exploit with SSL verification bypass.

CVE-2023-5360 PoC: Unauthenticated arbitrary file upload leading to RCE in Royal Elementor Addons (≤ 1.3.78), written in pure Python.

StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload

Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation