
TryHack3M-Bricks-Heist
🧱 CVE-2024-25600 WordPress Bricks Builder RCE Exploit + TryHackMe Bricks Heist CTF Write-up

🧱 CVE-2024-25600 WordPress Bricks Builder RCE Exploit + TryHackMe Bricks Heist CTF Write-up

Quick Review about the SQL-Injection in the NEX-Forms Plugin for WordPress

Abdal CVE-2026-63030 is a professional WordPress vulnerability scanner designed to detect exposure to CVE-2026-63030 through version analysis and…

A collection of useful resources for hacking WordPress and it's plugins and themes

This is a recurrence of cve-2019-9787 on Wordpress and a hash-based defense.

CVE-2024-5326 Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.1.2 - Missing Authorization to Arbitrary Options Update

Automates exploitation of CVE-2021-29447 in WordPress media upload to extract files via XXE, generating payloads and running an HTTP server for…

Demonstration of the WP Visitor Statistics plugin exploit

Static code analysis scanner for WordPress plugins and themes. Detects vulnerabilities like XSS and SQL injection via modular, extensible…

Wordpress likes and dislikes add-on - SQL Injection

WordPress CVE-2026-63030 and CVE-2026-60137 security tool for detecting exposure to the WP2Shell pre-authentication RCE chain.

The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated…

Proof-of-concept exploit for CVE-2026-7665, an unauthenticated information disclosure in Essential Addons for Elementor, allowing extraction of…

Unauthenticated SQL Injection exploit for WordPress Likes and Dislikes Plugin ≤ 1.0.0

Exploit for CVE-2025-10294: authentication bypass via empty HMAC key in ownid_shared_secret, enabling JWT forgery and unauthorized WordPress admin…

Exploit for CVE-2021-29447, an XXE vulnerability in WordPress 5.7.0 and earlier. Generates malicious WAV payloads to read arbitrary server files via…

Proof-of-concept for Denial of Service (DoS) attacks against WordPress 4.9.8 and 5.5 via unauthenticated requests to vulnerable admin pages, causing…

WordPress Likes and Dislikes Plugin <= 1.0.0 is vulnerable to SQL Injection