
CVE-2023-29384
CVE-2023-29384 Auto Exploiter on WordPress Job Board and Recruitment Plugin

CVE-2023-29384 Auto Exploiter on WordPress Job Board and Recruitment Plugin

Bash script for WordPress user enumeration and automated admin account creation, exploiting CVE-2026-23550 to bypass authentication and achieve…

WordPress pentest tool

PoC exploit chain for WordPress pre-auth XSS to RCE via DOM clobbering, REST JSONP/SOME, and plugin upload, with Docker lab verification and…

Authenticated PoC for CVE-2026-0911: tests weak file upload and orphan file behavior in WordPress Hustle plugin's module import endpoint, with…

PoC exploit for CVE-2023-5561 that enumerates WordPress user email addresses via the /wp-json/wp/v2/users API endpoint. For authorized security…

Local Docker lab demonstrating CVE-2026-5718 arbitrary file upload in a WordPress plugin, with vulnerable and patched services for side-by-side…

Proof-of-concept exploit for CVE-2023-4634, a remote code execution vulnerability in the WordPress Media Library Assistant plugin. Includes a…

Brute Force Wordpress Blogs.

Technical analysis and proof-of-concept exploit for CVE-2021-43408, a SQL injection vulnerability in the WordPress Duplicate Post plugin version…

Proof-of-concept exploit for CVE-2025-54352, a WordPress vulnerability that leaks titles of private and draft posts. Demonstrates the attack and…

WordPress社交登录和注册(Discord,Google,Twitter,LinkedIn)<=7.6.4-绕过身份验证

Exploit Windows server 2019 vulnerable to Zerologon with Garble, Chisel, wp-file-manager vulnerability (have video demo)

CVE-2025-54352 PoC

WP Directory Kit <= 1.4.4 - Authentication Bypass to Privilege Escalation via Account Takeover

exploit SQL injection ELEX WooCommerce Google Shopping

Exploit for CVE-2018-20555: automated discovery and takeover of Twitter accounts via leaked API keys in vulnerable Social Network Tabs WordPress…

WRecon, is a tool for the recognition of vulnerabilities and blackbox information for wordpress.