
wpprobe
A fast WordPress plugin enumeration tool

A fast WordPress plugin enumeration tool

Wordpress Hidden Login Page Disclosure. Detect Login Page Disclosure in WordPress sites running WPS Hide Login ≤ 1.9.15.2 (CVE-2024-2473)

WordPress WPS Hide Login <1.9.1 - Information Disclosure

Super Forms Unauthenticated File Upload RCE | CVSS 9.8

Chrome extension designed for WordPress Vulnerability Scanning and information gathering!

WRecon, is a tool for the recognition of vulnerabilities and blackbox information for wordpress.

WordPress Sites Vulnerability Checker for CVE-2020-35489 - "Educational Use Only"

Burp extension for wordpress security scanning

Non-intrusive checker for CVE-2026-63030 / CVE-2026-60137 ("wp2shell"), a pre-authentication RCE chain in WordPress core.

Scans WordPress sites for WP Time Capsule plugin CVE-2024-8856, detecting versions below 1.22.22 and logging vulnerable targets to a file.

cve-2021-38314 - Unauthenticated Sensitive Information Disclosure

WPScan rewritten in Python + some WPSeku ideas

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

Read-only CLI to check whether a WordPress site is exposed to WP2Shell (CVE-2026-63030 / CVE-2026-60137)

Mass exploitation tool for CVE-2026-8206 – Unauthenticated Privilege Escalation via 'handle_forgot_password' in Kirki WordPress plugin (≤6.0.6).

PoC detector & safe validator for the WP2Shell WordPress vulnerability chain: CVE-2026-63030 (REST batch-route confusion) + CVE-2026-60137…

Abdal CVE-2026-60137 is an advanced WordPress security scanner for identifying systems potentially affected by the CVE-2026-60137 SQL Injection…

Remote code execution exploit scripts for the WordPress File-Away plugin (CVE-2025-2512 & CVE-2025-2539)