
INPGer
Automatic Mass Tool for checking vulnerability in CVE-2022-4063 - InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE

Automatic Mass Tool for checking vulnerability in CVE-2022-4063 - InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE

Automatic Mass Tool for checking vulnerability in CVE-2023-0159 - Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated LFI

WPHunter A Wordpress Vulnerability Scanner

WordPress - Authenticated XXE (CVE-2021-29447)

PoC exploit for CVE-2019-6715: arbitrary file read in W3 Total Cache WordPress plugin via crafted SubscriptionConfirmation JSON. Reads files from…

CVE-2018-19487, CVE-2018-19488, exploit for WordPress wp-jobhunt plugin

This repository contains a Python script that checks WordPress websites for the CVE-2022-3590 vulnerability, which exploits an unauthenticated blind…

Wordpress Login Checker - no selenium / puppeteer

A PoC exploit for CVE-2017-5487 - WordPress User Enumeration.

WordPress File Upload插件任意文件读取漏洞(CVE-2024-9047)批量检测脚本

WordPress XXE vulnerability

WordPress does not properly restrict which user fields are searchable via the REST API, allowing unauthenticated attackers to discern the email…

WordPress Core <= 7.0.3 - Authenticated (Author+) Remote Code Execution via Malicious File Upload

Python exploit for CVE-2015-1579 targeting WordPress Slider Revolution Responsive <= 4.1.4. Executes remote file disclosure via crafted requests to…

Automatic Plugin for WordPress < 3.92.1 Multiples Vulnerabilities

Blackbox, non-intrusive detector for wp2shell (WordPress core pre-auth RCE, CVE-2026-63030 / CVE-2026-60137). Detection only.

POC - WordPress File Upload plugin, in the wfu_file_downloader.php file before version <= 4.24.11

wp2shell - WordPress RCE & PoC (CVE-2026-63030 + CVE-2026-60137)