
CVE-2025-6220
Ultimate Addons for Contact Form 7 <= 3.5.12 - Authenticated (Administrator+) Arbitrary File Upload via 'save_options'

Ultimate Addons for Contact Form 7 <= 3.5.12 - Authenticated (Administrator+) Arbitrary File Upload via 'save_options'

Ultimate Gift Cards for WooCommerce <= 3.0.6 - Missing Authorization to Infinite Money Glitch

Proof-of-concept exploit for CVE-2023-3460 enabling unauthorized admin access in the Ultimate Member WordPress plugin. Intended for educational…

React2Shell Ultimate - The most comprehensive CVE-2025-66478 Scanner for Next.js RSC RCE vulnerability. Multi-mode detection, WAF bypass, local…

This tool is a modern evolution of older PoCs like those for CVE-2017-7921 and ICSA-17-124-01, updated for 2025 with live console output, threading…

Proof-of-concept scripts demonstrating reflected XSS in the Ultimate Classified Listings WordPress plugin and admin cookie theft via crafted payloads…

Proof of concept for stored HTML injection in RISE CRM, demonstrating how authenticated users can inject malicious HTML into invoices and messages,…

Proof-of-concept exploit for CVE-2024-56278, a remote code execution vulnerability in the WP Ultimate Exporter WordPress plugin, demonstrating file…

Next.js RSC RCE vulnerability scanner with multiple scan modes, WAF bypass, interactive shell, and batch scanning for authorized penetration testing.

n8n God Mode Ultimate - CVE-2025-68613 Scanner v1.0.0 ║ ║ Workflow Automation Remote Code Execution

CVE-2025-3855 - RISE Ultimate Project Manager - IDOR

Unauthenticated SQL injection exploit for WordPress versions 2.1.3 to 2.8.2, targeting the Ultimate Member plugin to extract sensitive database…

The WooCommerce Ultimate Gift Card plugin for WordPress is vulnerable to arbitrary file uploads.

Proof-of-concept for stored XSS in RISE CRM item title field (CVE-2026-36392), demonstrating session hijacking and account takeover with remediation…

Proof-of-concept exploit for CVE-2023-3460 enabling unauthorized admin access in Ultimate Member WordPress plugin versions below 2.6.7. Intended for…

Ultimate Member Unauthorized Database Access / SQLi

Unauthenticated Arbitrary File/Folder Deletion in Joomla Helix Ultimate (JoomShaper) <= 2.2.6 — CVE-2026-57830

Exploit for the vulnerability of Ultimate Member Plugin.