
TryHack3M-Bricks-Heist
🧱 CVE-2024-25600 WordPress Bricks Builder RCE Exploit + TryHackMe Bricks Heist CTF Write-up

🧱 CVE-2024-25600 WordPress Bricks Builder RCE Exploit + TryHackMe Bricks Heist CTF Write-up

Quick Review about the SQL-Injection in the NEX-Forms Plugin for WordPress

A collection of useful resources for hacking WordPress and it's plugins and themes

This is a recurrence of cve-2019-9787 on Wordpress and a hash-based defense.

CVE-2024-5326 Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX <= 4.1.2 - Missing Authorization to Arbitrary Options Update

Automated tool to dump config.php files from vulnerable Joomla and WordPress websites using known exploit modules (com_joomanager, revslider).

Automates exploitation of CVE-2021-29447 in WordPress media upload to extract files via XXE, generating payloads and running an HTTP server for…

Proof-of-concept exploit for CVE-2024-5326, a missing authorization vulnerability in the PostX WordPress plugin allowing authenticated attackers to…

Demonstration of the WP Visitor Statistics plugin exploit

Wordpress likes and dislikes add-on - SQL Injection

WordPress CVE-2026-63030 and CVE-2026-60137 security tool for detecting exposure to the WP2Shell pre-authentication RCE chain.

The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated…

Unauthenticated SQL Injection exploit for WordPress Likes and Dislikes Plugin ≤ 1.0.0

Exploit for CVE-2025-10294: authentication bypass via empty HMAC key in ownid_shared_secret, enabling JWT forgery and unauthorized WordPress admin…

Exploit for CVE-2021-29447, an XXE vulnerability in WordPress 5.7.0 and earlier. Generates malicious WAV payloads to read arbitrary server files via…

WordPress Likes and Dislikes Plugin <= 1.0.0 is vulnerable to SQL Injection

Proof-of-concept scripts demonstrating reflected XSS in the Ultimate Classified Listings WordPress plugin and admin cookie theft via crafted payloads…

is a PoC tool designed to exploit insecurely exposed debug logs from WordPress sites and extract session cookies