FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

wordpress-exploit · GitHub Topics · GitHub

#

wordpress-exploit

Here are 27 public repositories matching this topic...

CVE-2023-32243 - Essential Addons for Elementor 5.4.0-5.7.1 - Unauthenticated Privilege Escalation

  • Updated Jun 5, 2023
  • Python

InfiniteWP Client < 1.9.4.5 - Authentication Bypass

  • Updated Jul 28, 2021
  • Python

WP2Shell - CVE-2026-63030 / CVE-2026-60137 This tool exploits a critical SQL injection vulnerability in the WordPress REST API `/wp-json/batch/v1` endpoint, allowing unauthenticated attackers to execute arbitrary SQL queries and achieve Remote Code Execution (RCE) on vulnerable WordPress installations.

  • Updated Jul 18, 2026
  • Python

Pix for WooCommerce <= 1.5.0 - Unauthenticated Arbitrary File Upload (CVE-2026-3891) PoC

  • Updated Mar 13, 2026
  • Python

Wordpress CVE-2023-32243

  • Updated May 30, 2026
  • Python

WordPress Pre-Auth RCE Exploit + Scanner + WAF Bypass | CVE-2026-63030 + CVE-2026-60137 | Go + Python + Metasploit modules + Docker lab

  • Updated Aug 8, 2026
  • Go

WP Maps Pro <= 6.1.0 - Unauthenticated Privilege Escalation via Administrator Account Creation to wpgmp_temp_access_ajax AJAX Action

  • Updated May 31, 2026
  • Python

PoC exploit for CVE-2026-2991 — authentication bypass in KiviCare WordPress plugin (≤4.1.2) allowing unauthenticated patient account takeover and admin session extraction.

  • Updated Mar 18, 2026
  • PHP

WPShell is an automated WordPress exploitation tool with auto shell deployment for fast security testing.

  • Updated Apr 16, 2026
  • Python

PoC for CVE-2026-3891 – Unauthenticated File Upload RCE in Pix for WooCommerce ≤ 1.5.0. Automated nonce retrieval, PHP upload, and command execution.

  • Updated Aug 3, 2026
  • Python

Automated tool for discovering WordPress uploaded files through intelligent brute force techniques with name variations, multi-threading, proxy support, and resume functionality.

  • Updated Jul 27, 2026
  • Python

WordPress SMTP Exploit

  • Updated Jun 2, 2026
  • Python

The tool targets WordPress websites that use the Super Backup & Clone plugin and are vulnerable to arbitrary file upload.

  • Updated May 30, 2026
  • Python

WordPress security audit & exploitation toolkit — fingerprinting, CVE database matching, 60+ active checks (hardening, misconfig, injection, plugin CVEs), exploitation simulation, and HTML/MD reporting.

  • Updated Jun 3, 2026
  • Python

The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthenticated users to register as an admin

  • Updated Jun 2, 2023
  • JavaScript

This is a Python script that exploits the CVE-2024-6624 vulnerability in the JSON API User <= 3.9.3 plugin for WordPress.

  • Updated May 30, 2026
  • Python

WordPress Remote File Inclusion

  • Updated Jun 2, 2026
  • Python

WordPress Content Injection Exploit

  • Updated Jun 2, 2026
  • Python

ProfilePress 3.0 - 3.1.3 - Unauthenticated Privilege Escalation

  • Updated Aug 9, 2023
  • Python

Improve this page

Add a description, image, and links to the wordpress-exploit topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the wordpress-exploit topic, visit your repo's landing page and select "manage topics."

Learn more


Back | FazBrowse Home | New Git URL