
CVE-2026-9055
Defensive analysis of CVE-2026-9055, an unauthenticated privilege escalation in Amelia WordPress booking plugin. Provides root cause breakdown,…

Defensive analysis of CVE-2026-9055, an unauthenticated privilege escalation in Amelia WordPress booking plugin. Provides root cause breakdown,…

WordPress Plugin Advanced Video 1.0 - Local File Inclusion Update

PoC for Unauthenticated Reflected Cross-Site Scripting (XSS) in RegistrationMagic WordPress Plugin

PoC for Unauthenticated Reflected Cross-Site Scripting (XSS) in RegistrationMagic WordPress Plugin

Exploit for unauthenticated Local File Inclusion (LFI) in WordPress Gecko theme <=1.9.8, allowing arbitrary file read including wp-config.php. Python…

Read-only CLI to check whether a WordPress site is exposed to WP2Shell (CVE-2026-63030 / CVE-2026-60137)

Safe passive detector for identifying WPMU DEV Dashboard versions affected by CVE-2026-76581.

Technical advisory and proof-of-concept for CVE-2026-12513, an unauthenticated arbitrary file deletion via path traversal in Shared Files WordPress…

Proof-of-concept exploit for CVE-2026-82222, an unauthenticated PHP object injection leading to remote code execution in GiveWP WordPress plugin…

Authorized Docker lab and clean PoC for validating CVE-2026-82222 RCE in GiveWP 4.16.5.1 and the 4.16.7.2 fix.

Proof-of-concept exploit for CVE-2024-56278, a remote code execution vulnerability in the WP Ultimate Exporter WordPress plugin, demonstrating file…

One-day proof-of-concept exploit for CVE-2026-19632, a critical unauthenticated account takeover in TranslatePress WordPress plugin, demonstrating…

Automated proof-of-concept for authenticated remote code execution in WordPress File Manager Pro (Filester) via arbitrary file upload, including…

An mini exploit for the Service Finder -Bookings plugin WP

Python proof-of-concept for CVE-2026-3844, an unauthenticated arbitrary file upload in WordPress Breeze Cache plugin, enabling remote code execution.…

Docker lab demonstrating CVE-2026-17532, an unauthenticated reflected XSS in Seraphinite Accelerator that chains to RCE via admin session, with…

Proof-of-concept exploit for CVE-2026-7567, an authentication bypass in WordPress Temporary Login Plugin <= 1.0.0, enabling account takeover. For…

Drop-in WordPress plugin that blocks the vulnerable Demo Import handler in FunnelForms Pro to mitigate Remote Code Execution (CVE-2026-39440).