
BurpCrypto
BurpSuite plugin for encrypting payloads with AES, RSA, DES, or custom JS code, enabling automated decryption of front-end encrypted traffic during…

BurpSuite plugin for encrypting payloads with AES, RSA, DES, or custom JS code, enabling automated decryption of front-end encrypted traffic during…

Exploit for CVE-2022-21661 targeting Elementor WordPress plugin, enabling SQL injection-based privilege escalation and data extraction.

PoC for CVE-2024-1512 in MasterStudy LMS WordPress Plugin.

Proof-of-concept exploit for a time-based blind SQL injection in the LearnPress WordPress plugin, allowing unauthenticated attackers to extract…

Proof of concept for unauthenticated sensitive data disclosure affecting the wp-import-export WordPress plugin (CVE-2022-0236)

Technical analysis of CVE-2025-0924, a Stored XSS vulnerability in WP Activity Log plugin for WordPress. Includes root cause analysis, exploitation…

RSVP ME <= 1.9.9 - Unauthenticated SQL Injection


Quick Review about the SQL-Injection in the NEX-Forms Plugin for WordPress

Exploit for CVE-2015-6668: CV filename disclosure vulnerability in the Job-Manager WordPress plugin. Demonstrates information gathering via path…

simple urls < 115 - Reflected XSS

All-in-one penetration testing platform with MITM proxy, web fuzzer, reverse connection handler, and plugin system for automated security testing and…

Authorized stored XSS assessment tool for CVE-2026-9271 in WordPress KeepInMind plugin. Detects vulnerable versions, injects safe test payloads, and…

Repository for CVE-2023-4549 vulnerability.

Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137)

Web Application Security Scanner

Repository for CVE-2023-4800 vulnerability.

Temporary WordPress plugin requiring authentication for the Core REST Batch API endpoint to mitigate the wp2shell vulnerability chain…