
CVE-2026-9055
Defensive analysis of CVE-2026-9055, an unauthenticated privilege escalation in Amelia WordPress booking plugin. Provides root cause breakdown,…

Defensive analysis of CVE-2026-9055, an unauthenticated privilege escalation in Amelia WordPress booking plugin. Provides root cause breakdown,…

Drop-in WordPress plugin that blocks the vulnerable Demo Import handler in FunnelForms Pro to mitigate Remote Code Execution (CVE-2026-39440).

Proof-of-concept exploit and technical advisory for an unauthenticated member PII disclosure in a WordPress REST API directory plugin, including…

JetEngine <= 3.7.2 - Authenticated (Contributor+) Remote Code Execution

CVE-2026-14483 POC EXPLOIT BY MADEXPLOITS

Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload

Proof-of-concept exploit for CVE-2023-4634, a remote code execution vulnerability in the WordPress Media Library Assistant plugin. Includes a…

Recencio Book Reviews - WordPress plugin for managing book reviews. Originally created by Kemory Grubb. Security-patched fork resolving…

(CVE-2024-51793) Wordpress Plugin: Computer Repair Shop <= 3.8115 - Unauthenticated Arbitrary File Upload

The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads.

Remote code execution exploit scripts for the WordPress File-Away plugin (CVE-2025-2512 & CVE-2025-2539)

CVE-2026-3296 is a CVSS 9.8 Critical unauthenticated PHP Object Injection vulnerability in the Everest Forms WordPress plugin

Unauthorized Arbitrary File Download in WordPress WP01

Python exploit script for CVE-2025-2294, an unauthenticated Local File Inclusion vulnerability in WordPress Kubio AI Page Builder ≤ 2.5.1. Supports…

Simple Dashboard <= 2.0 - Unauthenticated Privilege Escalation

Proof-of-concept exploit for CVE-2024-45590, demonstrating unauthenticated remote code execution in a WordPress plugin via arbitrary file upload.…

Proof-of-concept for CVE-2024-3552: SQL injection in WordPress Web Directory Free plugin (pre-1.7.0). Includes vulnerable code analysis, manual…

Automated exploit tool for CVE-2024-25600, enabling unauthenticated remote code execution on WordPress sites using the Bricks Builder plugin.…