
nginx-ultimate-bad-bot-blocker
Nginx Block Bad Bots, Spam Referrer Blocker, Vulnerability Scanners, User-Agents, Malware, Adware, Ransomware, Malicious Sites, with anti-DDOS,…

Nginx Block Bad Bots, Spam Referrer Blocker, Vulnerability Scanners, User-Agents, Malware, Adware, Ransomware, Malicious Sites, with anti-DDOS,…

PoC for CVE-2026-63030 + CVE-2026-60137, AKA WP2Shell

Automated scanner and exploiter for CVE-2024-13513 in Oliver POS WordPress plugin, checking vulnerable installations and changing password-reset…

A static code analysis for WordPress (and PHP)

PenBox - A Penetration Testing Framework - The Tool With All The Tools , The Hacker's Repo

Exploits CVE-2024-51793 unauthenticated arbitrary file upload in WordPress Computer Repair Shop plugin, scans target lists, uploads PHP webshells,…

Exploit for CVE-2022-21661 targeting Elementor WordPress plugin, enabling SQL injection-based privilege escalation and data extraction.

PoC for CVE-2024-1512 in MasterStudy LMS WordPress Plugin.

Proof-of-concept exploit for a time-based blind SQL injection in the LearnPress WordPress plugin, allowing unauthenticated attackers to extract…

CVE-2026-2576 — Business Directory Plugin SQLi PoC (Local Setup). Unauthenticated Time-Based Blind SQL Injection Business Directory Plugin for…

Unauthenticated privilege-escalation PoC for WordPress Events Manager < 7.4.1; discovers colliding post/user IDs and escalates targets to…

WPHunter A Wordpress Vulnerability Scanner

Technical analysis of CVE-2025-0924, a Stored XSS vulnerability in WP Activity Log plugin for WordPress. Includes root cause analysis, exploitation…

RSVP ME <= 1.9.9 - Unauthenticated SQL Injection


Exploit of the privilege escalation vulnerability of the WordPress plugin "WP GDPR Compliance" by "Van Ons"…

WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass

Quick Review about the SQL-Injection in the NEX-Forms Plugin for WordPress