
POC-AIOWPM-CVE-2026-19949
Reproducible Docker-based proof-of-concept for CVE-2026-19949, a second-order SQL injection in All-in-One WP Migration <= 7.109 that leaks the…

Reproducible Docker-based proof-of-concept for CVE-2026-19949, a second-order SQL injection in All-in-One WP Migration <= 7.109 that leaks the…

Generates a self-submitting HTML trigger page that exploits a reflected HTML injection in WordPress login (CVE-2026-64638) to display a custom…

CVE-2026-63030 & CVE-2026-60137 Wp2shell Poc

Python PoC for CVE-2026-8181, a critical authentication bypass in Burst Statistics WordPress plugin. Includes exploit automation, bulk scanning, and…

CVE-2026-63030 + CVE-2026-60137 - “wp2shell”: unauthenticated RCE in WordPress core

WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation

Automated auth bypass exploit for CVE-2025-0316 targeting WordPress WP Directorybox Manager. Features user enumeration, proxy support,…

Python exploit for CVE-2023-26326 (WordPress BuddyForms) chained with CVE-2024-2961 to achieve unauthenticated remote code execution via php://filter…

WP SuperBackup <= 2.3.3 - Unauthenticated Arbitrary File Upload

PoC exploit for CVE-2024-2667: automated arbitrary file upload and shell access via insufficient file validation in InstaWP Connect WordPress plugin…

Python Script that will DoS a WP server that is utilizing WP-CRON

Authenticated remote code execution exploit for WordPress WP All Import plugin <= 3.6.7 (CVE-2022-1565). Uploads arbitrary files via insecure file…