Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories

Tools

AllAndroid SecurityAuthentication & AuthorizationCloud Infrastructure SecurityDefensive ToolsDisk ForensicsEmbedded Systems SecurityGeneral Purpose UtilitiesIndicator of Compromise (IOC) ManagementOSINT (Open Source Intelligence)Packet Sniffing & AnalysisPassword CrackingPenetration Testing FrameworksPhishing ToolsPrivilege EscalationReconnaissanceStatic AnalysisVulnerability ScannersWeb Vulnerability ScannersWi-Fi AuditingBluetooth SecurityContainer SecurityDynamic Analysis (Sandboxing)Encryption/Decryption ToolsExploit FrameworksIdentity ManagementiOS SecurityIoT SecurityMemory ForensicsNetwork MappingOSINT for Social EngineeringPassword AttacksPayload GenerationPersistence MechanismsPort ScanningStatic Code Analysis (SAST)Threat Feeds & AggregatorsVulnerability AnalysisWeb Proxies & InterceptionCode AnalysisDNS & Subdomain EnumerationDynamic Code Analysis (DAST)ExploitationHash AnalysisIDS/IPS EvasionImpersonation ToolsLateral MovementMobile App PentestingNetwork ForensicsReverse EngineeringRFID/NFC ToolsSCADA/ICS SecurityScripting & AutomationServerless SecurityShellcodeWeb Application ExploitationAPI Security TestingConfiguration AuditingData ExfiltrationDebuggersForensicsInformation GatheringMobile ForensicsNetwork Access ControlPost-ExploitationSecurity VirtualizationPhishingWAF BypassWeb SecurityFuzzingNetwork SecuritySteganographyWireless SecurityData RecoveryMalware AnalysisDigital ForensicsHardware HackingCryptographyCTFPenetration TestingCloud SecurityDevSecOpsMobile SecurityPrivacyCommand and ControlSocial EngineeringHardware SecurityUtilities & FrameworksHardware & IoT SecuritySecret DetectionBinary AnalysisThreat IntelligenceIdentity & Access Management (IAM)Supply Chain SecurityAuthenticationMachine LearningIntrusion DetectionPapers & ResearchMisconfigurationSubdomain EnumerationEmail HarvestingLearning & EducationAI-Assisted ReversingDNS FuzzingRed TeamingIncident ResponseCrawlerCurated ResourcesRemote Access ToolShellcode GenerationPayload DevelopmentRemote Access TrojanAPI SecurityAnti-BotFingerprint SpoofingCAPTCHA BypassEmail SecurityDNS AnalysisChaos EngineeringLearning Paths & CoursesContainer EscapeAI SecurityDatabase SecurityFirmware AnalysisAnomaly DetectionLog AnalysisAdversarial AttackBinary ExploitationLabs & Practice
NewestRelevanceMost popularRecently updated
1170 results
wpjuicer preview

wpjuicer

GitHubtaurusomar/wpjuicer

WP Juicer Tool for quick scanning of confidential information on WordPress endpoints.

information-gatheringreconnaissancevulnerability-scanners+1
10
2 years ago
CVE-2025-7401 preview

CVE-2025-7401

GitHubnxploited/cve-2025-7401

Premium Age Verification / Restriction for WordPress <= 3.0.2 - Unauthenticated Arbitrary File Read and Write

data-exfiltrationexploitationinformation-gathering+5
211 months ago
CVE-2021-38314 preview

CVE-2021-38314

GitHubshubhayu-64/cve-2021-38314

Proof-of-concept exploit for CVE-2021-38314 enabling unauthenticated sensitive information disclosure in WordPress plugins. Useful for security…

exploitationinformation-gatheringpenetration-testing+2
14 years ago
CVE-2024-10470 preview

CVE-2024-10470

GitHubrandomrobbiebf/cve-2024-10470

WPLMS Learning Management System for WordPress <= 4.962 – Unauthenticated Arbitrary File Read and Deletion

exploitationinformation-gatheringpenetration-testing+2
1 year ago
CVE-2022-3590-WordPress-Vulnerability-Scanner preview

CVE-2022-3590-WordPress-Vulnerability-Scanner

GitHubhuynhvanphuc/cve-2022-3590-wordpress-vulnerability-scanner

Python script to detect unauthenticated blind SSRF (CVE-2022-3590) in WordPress pingback feature. Supports single URL and batch scanning with…

exploitationinformation-gatheringpenetration-testing+3
2 years ago
CVE-2025-3102 preview

CVE-2025-3102

GitHubsupraaa-1337/cve-2025-3102

Detects the version of the SureTriggers WordPress plugin from exposed asset URLs and compares it to determine if it's vulnerable (<= 1.0.78).

exploitationinformation-gatheringreconnaissance+2
1 year ago
Check-WP-CVE-2020-35489 preview

Check-WP-CVE-2020-35489

GitHubdn9uy3n/check-wp-cve-2020-35489

The (WordPress) website test script can be exploited for Unlimited File Upload via CVE-2020-35489

exploitationpenetration-testingvulnerability-scanners+2
312 years ago
wp2shell-scan preview

wp2shell-scan

GitHubfullhunt/wp2shell-scan

A scanner and proof-of-concept toolkit for CVE-2026-63030 (wp2shell) - pre-authenticated remote code execution in WordPress core

exploitationpenetration-testingred-teaming+2
51 month ago
wp2shell-poc preview

wp2shell-poc

GitHubdeadexpl0it/wp2shell-poc

wp2shell — WordPress Core Pre-Auth RCE Chain poc for CVE-2026-63030 and CVE-2026-60137

ctfeducationexploitation+5
13 days ago
Python-exploit-CVE-2020-25213 preview

Python-exploit-CVE-2020-25213

GitHubbly-coder/python-exploit-cve-2020-25213

Python exploit for RCE in Wordpress

exploitationpayload-generationpenetration-testing+3
63 years ago
Check-WP-CVE-2020-35489 preview

Check-WP-CVE-2020-35489

GitHubx0ucyb3r/check-wp-cve-2020-35489

Python script to detect WordPress sites vulnerable to CVE-2020-35489 in Contact Form 7, allowing unrestricted file uploads. Scans domains or lists…

exploitationpenetration-testingvulnerability-scanners+2
25 years ago
CVE-2026-40776 preview

CVE-2026-40776

GitHublorenzofradeani/cve-2026-40776

CVE-2026-40776 — Broken Access Control + IDOR in WordPress Eventin (wp-event-solution) <= 4.1.8

educationexploitationpapers-research+3
23 months ago
CVE-2024-49668 preview

CVE-2024-49668

GitHubnxploited/cve-2024-49668

WordPress Verbalize WP plugin <= 1.0 - Arbitrary File Upload vulnerability

educationexploitationpayload-generation+3
21 year ago
CVE-2025-15521 preview

CVE-2025-15521

GitHubnxploited/cve-2025-15521

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account…

authenticationexploitationinformation-gathering+5
14 months ago
EXPLOIT-CVE-2026-8832 preview

EXPLOIT-CVE-2026-8832

GitHubfunixone/exploit-cve-2026-8832

Automated RCE exploit for WordPress WPCode Lite v2.3.5 (CVE-2026-8832) with 8 built-in PHP payloads, XML-RPC bypass, and web-based interactive shell…

code-analysisexploitationpayload-development+5
13 months ago
wp2shell-compromise-scanner-plugin preview

wp2shell-compromise-scanner-plugin

GitHubeyesecurity/wp2shell-compromise-scanner-plugin

Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137)

database-securitydigital-forensicsforensics+5
1 month ago
CVE-2024-9593-Exploit preview

CVE-2024-9593-Exploit

GitHubnxploited/cve-2024-9593-exploit

PoC exploit for CVE-2024-9593 exploiting unauthenticated remote code execution in WordPress Time Clock plugin. Python script invokes vulnerable…

educationexploitationpenetration-testing+3
11 year ago
CVE-2025-11391 preview

CVE-2025-11391

GitHubmoritakaaz/cve-2025-11391

WordPress PPOM for WooCommerce Plugin <= 33.0.15 is vulnerable to SQL Injection

database-securityeducationexploitation+4
10 months ago
Previous1…91011…65Next