
wpjuicer
WP Juicer Tool for quick scanning of confidential information on WordPress endpoints.

WP Juicer Tool for quick scanning of confidential information on WordPress endpoints.

Premium Age Verification / Restriction for WordPress <= 3.0.2 - Unauthenticated Arbitrary File Read and Write

Proof-of-concept exploit for CVE-2021-38314 enabling unauthenticated sensitive information disclosure in WordPress plugins. Useful for security…

WPLMS Learning Management System for WordPress <= 4.962 – Unauthenticated Arbitrary File Read and Deletion

Python script to detect unauthenticated blind SSRF (CVE-2022-3590) in WordPress pingback feature. Supports single URL and batch scanning with…

Detects the version of the SureTriggers WordPress plugin from exposed asset URLs and compares it to determine if it's vulnerable (<= 1.0.78).

The (WordPress) website test script can be exploited for Unlimited File Upload via CVE-2020-35489

A scanner and proof-of-concept toolkit for CVE-2026-63030 (wp2shell) - pre-authenticated remote code execution in WordPress core

wp2shell — WordPress Core Pre-Auth RCE Chain poc for CVE-2026-63030 and CVE-2026-60137

Python exploit for RCE in Wordpress

Python script to detect WordPress sites vulnerable to CVE-2020-35489 in Contact Form 7, allowing unrestricted file uploads. Scans domains or lists…

CVE-2026-40776 — Broken Access Control + IDOR in WordPress Eventin (wp-event-solution) <= 4.1.8

WordPress Verbalize WP plugin <= 1.0 - Arbitrary File Upload vulnerability

The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to privilege escalation via account…

Automated RCE exploit for WordPress WPCode Lite v2.3.5 (CVE-2026-8832) with 8 built-in PHP payloads, XML-RPC bypass, and web-based interactive shell…

Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137)

PoC exploit for CVE-2024-9593 exploiting unauthenticated remote code execution in WordPress Time Clock plugin. Python script invokes vulnerable…

WordPress PPOM for WooCommerce Plugin <= 33.0.15 is vulnerable to SQL Injection