
Wordpress-ebook-CVE-2016-10924
Exploits CVE-2016-10924 file disclosure in WordPress eBook Download plugin to brute-force server processes and retrieve sensitive files.

Exploits CVE-2016-10924 file disclosure in WordPress eBook Download plugin to brute-force server processes and retrieve sensitive files.

Unauthenticated 0-click RCE exploit for CVE-2024-51793. Exploits an arbitrary file upload vulnerability via admin-ajax.php to upload a PHP payload…

Exploit and scanner for CVE-2023-3460, a WordPress Ultimate Member plugin privilege escalation vulnerability allowing unauthenticated admin account…

Technical analysis and defensive mitigation for a WordPress Core pre-auth XSS-to-RCE chain, including sanitizer bypass, DOM clobbering, JSONP abuse,…

Docker-based lab for reproducing CVE-2026-49060, an unauthenticated privilege escalation in the Hippoo Mobile App for WooCommerce WordPress plugin.…

Python exploit script for CVE-2024-6624 targeting unauthenticated privilege escalation in the JSON API User WordPress plugin. Automates user…

Proof-of-concept exploit for CVE-2025-6792 demonstrating unauthorized Pusher channel subscription and event eavesdropping in a WordPress plugin via…

Proof-of-concept exploit for CVE-2023-47504 targeting Elementor WordPress plugin. Requires subscriber credentials and wp-config.php access to delete…

Proof-of-concept exploit for CVE-2024-27956, a SQL injection in ValvePress Automatic WordPress plugin. Creates admin user and enables remote code…

Exploit and analysis of CVE-2023-3460, a critical privilege escalation in the Ultimate Member WordPress plugin, with reproduction environment and…

Wordpress Video Gallery - YouTube Gallery and Vimeo Gallery Plugin SQL Injection

Exploit scripts and scanner for CVE-2024-27956, a WordPress plugin vulnerability, including a modified exploit with SSL verification bypass.

Python exploit script and Nuclei template for CVE-2023-37979, a reflected XSS vulnerability in the Ninja-forms WordPress plugin, enabling automated…

Automated scanner and exploiter for CVE-2024-13513 in Oliver POS WordPress plugin, checking vulnerable installations and changing password-reset…

Exploit PoC for unauthenticated doctor/receptionist account creation in the KiviCare WordPress plugin via improper privilege management, providing…

Asynchronous WordPress security scanner with WAF bypass via headless browser. Enumerates plugins, themes, users, and multisite installations with…

Proof-of-concept exploit for CVE-2026-64638: reflected XSS in WordPress login chained with DOM clobbering to achieve admin account takeover and…

Independent root cause analysis and proof-of-concept for unauthenticated SQL injection to RCE in WordPress (CVE-2026-63030 + CVE-2026-60137), with…