
wpscan
WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

WordPress security scanner that detects vulnerabilities, enumerates plugins/themes/users, and checks for weak passwords. Integrates with the WPScan…

Egyscan The Best web vulnerability scanner; it's a multifaceted security powerhouse designed to fortify your web applications against malicious…

Web Application Security Scanner

Scans WordPress Forminator for CVE-2026-15748 unauthenticated RCE. Detects vulnerable sites, crawls forms, extracts nonces, runs safe upload tests.

Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator

Non-destructive detector for CVE-2026-64638 (XSS2Shell) — WordPress pre-auth XSS reflection primitive

Nikto web server scanner

CVE-2026-56292 - AcyMailing for Joomla unauthenticated SQL injection scanner

Passive security checker for CVE-2026-48908 affecting SP Page Builder.

Free web-application vulnerability and version scanner

CVE-2026-64638: WordPress Pre-auth XSS → RCE (XSS2Shell) PoC

Safe PowerShell validator for PHP CVE-2026-17543 exposure via HTTP headers and non-destructive login-form probes.

Modern tactical exploitation toolkit.

OWASP Web Recon & Directory Discovery Platform

PressVector - Advanced WordPress Vulnerability Scanner CVE-2026-63030 (REST batch route confusion) / CVE-2026-60137 (SQLi) Developer: Vulnquest

Nuclei scripts created by @rxerium for zero days / actively exploited vulnerabilities.

Non-intrusive checker for CVE-2026-63030 / CVE-2026-60137 ("wp2shell"), a pre-authentication RCE chain in WordPress core.

Proof-of-concept exploit for reflected cross-site scripting (XSS) vulnerability in Trimble TM4WEB <=22.2.0, demonstrating injection via arbitrary URL…