
wp2shell-vulnerability-scanner
Scan WordPress installations for wp2shell vulnerabilities (CVE-2026-63030 + CVE-2026-60137). Identifies full RCE and SQL injection risks across…

Scan WordPress installations for wp2shell vulnerabilities (CVE-2026-63030 + CVE-2026-60137). Identifies full RCE and SQL injection risks across…

Royal Elementor Addons - Unauthenticated Remote Code Execution

Mass CVE-2023-2744

snapcreek_duplicator file read vulnerability https://www.cvedetails.com/cve/CVE-2020-11738/

Async mass-checker for authorized internal testing of CVE-2026-2631 exposure.

Chrome extension designed for WordPress Vulnerability Scanning and information gathering!

CMS Detection and Exploitation suite - Scan WordPress, Joomla, Drupal and over 180 other CMSs

WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass

Automated exploitation tool targeting CMS vulnerabilities in Joomla, WordPress, Drupal, PrestaShop, and OsCommerce with built-in brute-force and…

CVE-2026-9848 is an Unauthenticated SQL Injection (SQLi) vulnerability affecting the WP Ticket (Customer Support Ticket System & Helpdesk) plugin for…

This is an exploit script to find out wordpress admin's username and password hash by exploiting CVE-2024-1698.

Read-only WordPress security scanner for HestiaCP servers. Detects wp2shell compromise indicators (CVE-2026-63030 / CVE-2026-60137) across all hosted…

Proof-of-concept exploit for CVE-2020-24148, a server-side request forgery (SSRF) vulnerability in the WordPress Import XML and RSS Feeds plugin via…

Docker-based lab for reproducing and validating CVE-2026-56011, an unauthenticated XSS vulnerability in MapPress Maps for WordPress, with vulnerable…

WordPress Custom Login And Signup Widget Plugin <= 1.0 is vulnerable to Arbitrary Code Execution

WordPress Frontend Login and Registration Blocks Plugin <= 1.0.7 is vulnerable to Privilege Escalation

WordPress Meta Data and Taxonomies Filter (MDTF) <= 1.3.3.4 - Unauthenticated Arbitrary Shortcode Execution

Proof-of-concept exploit for CVE-2025-2568, demonstrating unauthorized access and modification of WordPress Vayu Blocks plugin options via missing…