
wp2shell-rce
WordPress CVE-2026-63030 and CVE-2026-60137 security tool for detecting exposure to the WP2Shell pre-authentication RCE chain.

WordPress CVE-2026-63030 and CVE-2026-60137 security tool for detecting exposure to the WP2Shell pre-authentication RCE chain.

wp2shell - WordPress RCE & PoC (CVE-2026-63030 + CVE-2026-60137)

WordPress security scanner that fingerprints versions, detects reflected XSS across multiple targets concurrently, and supports an authenticated…

WordPress mass scanner for detecting CVE-2026-1405 exposure.

Wordell is a powerful WordPress enumeration script designed to make your WordPress security assessments more efficient and comprehensive. It enables…

PressVector - Advanced WordPress Vulnerability Scanner CVE-2026-63030 (REST batch route confusion) / CVE-2026-60137 (SQLi) Developer: Vulnquest

Graphical exploit for CVE-2025-3102 in WordPress SureTriggers plugin, enabling unauthenticated admin user creation via API. Includes vulnerable site…

WordPress Core Pre-Auth RCE — Batch Route Confusion + SQL Injection

Non-intrusive exposure checker for the WordPress wp2shell pre-auth RCE chain (CVE-2026-63030 / CVE-2026-60137).

Non-intrusive detection scanner for the WordPress wp2shell pre-auth RCE chain (CVE-2026-63030 + CVE-2026-60137). Detection-only, no exploitation.

Scan WordPress installations for wp2shell vulnerabilities (CVE-2026-63030 + CVE-2026-60137). Identifies full RCE and SQL injection risks across…

CVE-2024-25600 - Unauthenticated RCE exploit for WordPress Bricks Builder Theme. Advanced exploitation framework with interactive shell, reverse…

Authorized WordPress XSS-to-RCE scanner with concurrent multi-target XSS reflection and version fingerprint detection, plus optional exploitation…

Tool to extract all themes and plugins that are shown on the front page of a wordpress site.

Identifies domains which run WordPress and tests against vulnerabilities (CVE-2023-32243) / #VU76395 / etc...

Multi-threaded Python scanner for CVE-2026-23550, detecting unauthenticated admin takeover in WordPress Modular DS plugin with full wp-admin…

Proof-of-concept exploit for a critical SQL injection vulnerability in WordPress Email Subscribers plugin. Includes exploitation details, HTTP…

Proof-of-concept exploit for CVE-2019-17671, a WordPress plugin vulnerability exploitable via crafted URL parameters to achieve unauthorized data…