
CVE-2022-21661
A Python PoC for CVE-2022-21661, adapted from z92g's Go PoC, designed to demonstrate the vulnerability in a more accessible scripting environment.

A Python PoC for CVE-2022-21661, adapted from z92g's Go PoC, designed to demonstrate the vulnerability in a more accessible scripting environment.

Safe passive detector for identifying WPMU DEV Dashboard versions affected by CVE-2026-76581.

NekoBot | Auto Exploiter With 500+ Exploit 2000+ Shell

WORDPRESS

CMS Scanner: Scan Wordpress, Drupal, Joomla, vBulletin websites for Security issues

Plecost - Professional WordPress Security Scanner

LiteSpeed Cache plugin for WordPress that could enable unauthenticated users to escalate their privileges

Non-intrusive checker for CVE-2026-63030 / CVE-2026-60137 ("wp2shell"), a pre-authentication RCE chain in WordPress core.

cve-2021-38314 - Unauthenticated Sensitive Information Disclosure

WPScan rewritten in Python + some WPSeku ideas

Unauthenticated Sensitive Information Disclosure (CVE-2021–38314).

Wordpress XMLRPC System Multicall Brute Force Exploit (0day) by 1N3 @ CrowdShield

Unauthenticated RCE exploit for CVE-2024-25600 in WordPress Bricks Builder <= 1.9.6. Executes arbitrary code remotely.

Python exploit for Jetpack < 13.9.1 broken access control (CVE-2024-9926). Allows authenticated users to read visitor-submitted forms on WordPress…

Wordpress CVE-2023-34960

An XMLRPC brute forcer targeting Wordpress written in Python 3. (DISCONTINUED)

Automatic Mass Tool for checking vulnerability in CVE-2022-1386 - Fusion Builder < 3.6.2 - Unauthenticated SSRF

CVE-2026-39492 — WP Maps (wp-google-map-plugin) <= 4.9.1 Unauthenticated Blind SQL Injection Mass Scanner | sqlmap-style detection | backtick bypass…