
CVE-2018-6389
Proof-of-concept DoS exploit for CVE-2018-6389 targeting WordPress load-scripts.php, with Docker-based test environment and automated doser.py…

Proof-of-concept DoS exploit for CVE-2018-6389 targeting WordPress load-scripts.php, with Docker-based test environment and automated doser.py…

Exploit chain for WordPress Core using REST API route-confusion and SQL injection for unauthenticated RCE, privilege escalation, and full server…

Python Interactive Exploit for WP File Manager Vulnerability. The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote…

Unauthenticated remote code execution exploit for the WC Designer Pro WordPress plugin. Automates detection, file upload, and shell access via a…

Pre-auth RCE exploit for WordPress (CVE-2026-63030 + CVE-2026-60137) chaining route confusion and SQL injection into full shell access. Includes…

PHP Object Injection exploit for WP Insightly (CVE-2026-49085). Provides proof-of-concept code to demonstrate and test the vulnerability in affected…

Time-based SQL injection exploit for CVE-2025-11177 targeting WordPress login with curl-based payload delivery and pg_sleep timing detection.

Exploit and proof-of-concept for arbitrary file deletion in Perfmatters WordPress plugin (CVE-2026-4350), with Python exploit and bash POC scripts…

Proof-of-concept exploit for CVE-2025-11986 demonstrating unauthenticated access bypass in WordPress crypto_connect plugin via nonce extraction and…

Lab environment and proof-of-concept exploit for CVE-2026-1357, a WordPress plugin vulnerability, with Docker setup and automated exploitation…

Modular exploit framework targeting CVE-2026-23550 in WordPress, featuring mass exploitation, obfuscation, post-exploitation, and Docker-based C2…

Proof-of-concept exploit for CVE-2024-27956: SQL injection in WordPress leading to admin account creation and remote code execution. Written in…

Proof-of-concept exploit for CVE-2025-8625 targeting WordPress, with Docker-based isolated lab environment and demonstration web shell for…

WordPress Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light Plugin <= 2.4.37 is vulnerable to Privilege Escalation

Proof-of-concept and technical analysis for CVE-2022-21661, a WordPress SQL injection vulnerability, including root-cause breakdown, exploitation…

Exploit for CVE-2020-9006 targeting WordPress Popup-Builder plugin via SQL injection and PHP deserialization, with payload generation and Nmap…

Proof-of-concept exploit for CVE-2022-21661, a SQL injection vulnerability in WordPress Core WP_Query, demonstrating the attack and providing…

Exploit script for CVE-2024-25600, a remote code execution vulnerability in WordPress Bricks Builder, with multi-POC support and configurable threads.