


A fast WordPress plugin enumeration tool

OSCP-legal network recon orchestrator for port discovery, service classification, and enum-only plugin dispatch across HTTP, SMB, FTP, SNMP, SSH, and…

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

Reproducer for CVE-2026-64640 — Apache Polaris Iceberg REST register/register-view vends storage credentials and reads an attacker-chosen metadata…

Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upload to Remote Code Execution

CVE-2026-8181 — Burst Statistics WordPress plugin Authentication Bypass (CVSS 9.8) to Admin Account Takeover. Mass scanner with FOFA/Shodan…

CVE-2026-49049 Helix3 (JoomShaper) Joomla Unauthenticated AJAX RCE Scanner

Proof-of-concept exploit for Grafana path traversal vulnerability (CVE-2021-43798) allowing unauthorized file read via directory traversal in plugin…

Mass exploit toolkit for CVE-2026-5524, an unauthenticated file upload RCE in Divi Form Builder. Features multi-threaded scanning, WAF bypass…

Mass exploitation tool for CVE-2026-8206 – Unauthenticated Privilege Escalation via 'handle_forgot_password' in Kirki WordPress plugin (≤6.0.6).

Multi-threaded mass scanner for CVE-2026-8732 in WordPress WP Google Map Pro. Automates nonce extraction, token exploitation, and hidden admin…

Scans WordPress sites for WP Time Capsule plugin CVE-2024-8856, detecting versions below 1.22.22 and logging vulnerable targets to a file.

High-performance OSINT/CTI framework for automated identity pivoting and risk analysis across 120+ sources.

Unauthenticated SSRF in Chamilo LMS via PENS plugin (pens.php) — CVSS 7.5

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account…

WordPress Simple Link Directory Plugin < 14.8.1 is vulnerable to a high priority Broken Authentication

CVE-2026-3584