
CVE-2026-32488
Proof-of-concept exploit for CVE-2026-32488 targeting WordPress user registration via crafted POST requests to admin-ajax.php, enabling…

Proof-of-concept exploit for CVE-2026-32488 targeting WordPress user registration via crafted POST requests to admin-ajax.php, enabling…

Wordpress Plugin Simple Job Board 2.9.3 LFI Vulnerability (CVE-2020-35749) proof of concept exploit

WordPress Simple File List FileRead POC

Proof-of-concept exploit for CVE-2025-4524, a Local File Inclusion vulnerability in WordPress Madara theme versions below 2.2.2.1, enabling…

CVE-2026-11961 — UserRegistration: WordPress User Registration <= 5.2.2 Privilege Escalation. Misconfigured Membership Roles → Unauthenticated Admin…

Proof-of-concept exploit for CVE-2024-2876, an unauthenticated SQL injection vulnerability in the Email Subscribers plugin for WordPress, enabling…

Proof-of-concept exploit for CVE-2026-3180, a blind SQL injection in WordPress Contest Gallery plugin. Demonstrates boolean-based injection via…

Non-intrusive detection scanner for the WordPress wp2shell pre-auth RCE chain (CVE-2026-63030 + CVE-2026-60137). Detection-only, no exploitation.

Non-intrusive exposure checker for the WordPress wp2shell pre-auth RCE chain (CVE-2026-63030 / CVE-2026-60137).

Wordpress Hidden Login Page Disclosure. Detect Login Page Disclosure in WordPress sites running WPS Hide Login ≤ 1.9.15.2 (CVE-2024-2473)

Unauthenticated SQL injection exploit for WordPress versions 2.1.3 to 2.8.2, targeting the Ultimate Member plugin to extract sensitive database…

Exploit for CVE-2015-6668: CV filename disclosure vulnerability in the Job-Manager WordPress plugin. Demonstrates information gathering via path…

Updated POC for Unauth Post Author Email Disclosures WordPress CVE-2023-5561

LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_only_fields'

CVE-2024-4443 Business Directory Plugin – Easy Listing Directories for WordPress <= 6.4.2 - Unauthenticated SQL Injection via listingfields Parameter

Multi-threaded Python scanner for CVE-2026-23550, detecting unauthenticated admin takeover in WordPress Modular DS plugin with full wp-admin…

POC to exploit WordPress 5.6-5.7 (PHP 8+) Authenticated XXE Injection.

Exploit for CVE-2026-0926 targeting Local File Inclusion in the Prodigy Commerce WordPress plugin. Enables reading arbitrary files on vulnerable…