This is your work, valued

UK,Liverpool

Robert Wiggins

Elite
@RandomRobbieBF

The UK guy working at BishopFox who seems to have far too many wordpress exploits

CVE-2023-32243. CVE-2023-32243 - Essential Addons for Elementor 5.4.0-5.7.1 - Unauthenticated Privilege Escalation

85

grafana-ssrf. Authenticated SSRF in Grafana

83

marshalsec-jar. marshalsec-0.0.3-SNAPSHOT-all compiled on X64

82

CVE-2023-2982. WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass

81

CVE-2023-7028. CVE-2023-7028

58

phpunit-brute. Tool to try multiple paths for PHPunit RCE CVE-2017-9841

30

wordpress-plugin-list. Wordpress Plugins List for Bruteforcing.

24

nuclei-drupal-sa. Nuclei templates for drupal vulns... far from perfect

18

service-now. Service-Now Article Bruteforcer

16

wp-file-manager. wp-file-manager RCE

9

CVE-2024-9593. Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code Execution

8

CVE-2023-32117. Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints

6

CVE-2024-49328. WP REST API FNS <= 1.0.0 - Privilege Escalation

6

kong-pwn. Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls

6

CVE-2023-2732. MStore API <= 3.9.2 - Authentication Bypass

6

super-secret-finder. Burp Plugin for Secret Matching

6

CVE-2023-5204. AI ChatBot <= 4.8.9 - Unauthenticated SQL Injection via qc_wpbo_search_response

5

redash-reset. Python

5

CVE-2023-5412. Image horizontal reel scroll slideshow <= 13.2 - Authenticated (Subscriber+) SQL Injection via Shortcode

5

coldfusion-amf. Coldfusion AMF PWN

5

CVE-2022-0952. Sitemap by click5 < 1.0.36 - Unauthenticated Arbitrary Options Update

5

CVE-2024-22145. InstaWP Connect <= 0.1.0.8 - Missing Authorization to Arbitrary Options Update (Subscriber+)

4

CVE-2024-10924. Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 – 9.1.1.1 – Authentication Bypass

4

Log4J-Exploits. Log4J Exploits for Different Systems

4

CVE-2024-9796. WordPress WP-Advanced-Search <= 3.3.9 - Unauthenticated SQL Injection

4

simple-file-list-rce. Simple File List < 4.2.3 - Unauthenticated Arbitrary File Upload RCE

4

CVE-2024-9932. Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload

3

CVE-2024-9061. WP Popup Builder – Popup Forms and Marketing Lead Generation <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via wp_ajax_nopriv_shortcode_Api_Add

3

wordpress-exploits. Random Wordpres Exploits May or May Not Work.

3

wordpress-php-object-helper. Know a plugin has a php object exploit but need to find which lib to use?

3

CVE-2024-50498. WP Query Console <= 1.0 - Unauthenticated Remote Code Execution

3

CVE-2023-47840. Qode Essential Addons <= 1.5.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation

3

CVE-2024-6624. JSON API User <= 3.9.3 - Unauthenticated Privilege Escalation

3

CVE-2022-3904. CVE-2022-3904 MonsterInsights < 8.9.1 - Stored Cross-Site Scripting via Google Analytics

3

CVE-2024-49681. WP Sessions Time Monitoring Full Automatic <= 1.0.9 - Unauthenticated SQL Injection

3

CVE-2024-0679. ColorMag <= 3.1.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation

2

CVE-2024-12025. Collapsing Categories <= 3.0.8 - Unauthenticated SQL Injection

2

woo. Exploit woocommerce SQLI and grab user and password hash

2

csp-log4j. Finds CSP report urls and tests to see if they are vulnerable to log4j

2

CVE-2024-9935. PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Unauthenticated Arbitrary File Download

2

Rogue-MySql-Server. MySQL fake server for read files of connected clients

2

what-wordpress. Tool to extract all themes and plugins that are shown on the front page of a wordpress site.

2

dom-brute. Domain TLD prefix finder / 3rd party hosted.

2

CVE-2023-2877. Formidable Forms < 6.3.1 - Subscriber+ Remote Code Execution

2

CVE-2023-0630. CVE-2023-0630 - Slimstat Analytics < 4.9.3.3 - Subscriber+ SQL Injection

2

CVE-2024-9234. GutenKit <= 2.1.0 - Unauthenticated Arbitrary File Upload

2

SAP-brute. SAP Netweaver Login Bruteforcer.

2

CVE-2024-50483. Meetup <= 0.1 - Authentication Bypass via Account Takeover

2

CVE-2023-6700. Cookie Information | Free GDPR Consent Solution <= 2.0.22 - Authenticated (Subscriber+) Arbitrary Options Update

2

CVE-2024-8529. LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'

2

CVE-2024-2387. Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms <= 1.82.0 - SQL Injection to Reflected Cross-Site Scripting via integration_id

2

CVE-2025-5701. HyperComments <= 1.2.2 - Unauthenticated (Subscriber+) Arbitrary Options Update

2

django-bruteforce. Django Admin Url Bruteforce tool.

2

CVE-2025-22954. Koha CVE-2025-22954: SQL Injection in lateissues-export.pl

2

CVE-2024-13800. Popup Plugin For WordPress - ConvertPlus <= 3.5.30 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update

2

CVE-2024-11423. Ultimate Gift Cards for WooCommerce <= 3.0.6 - Missing Authorization to Infinite Money Glitch

2

CVE-2024-56064. WP SuperBackup <= 2.3.3 - Unauthenticated Arbitrary File Upload

2

CVE-2024-55988. Navayan CSV Export <= 1.0.9 - Unauthenticated SQL Injection

2

CVE-2024-12209. WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion

1

CVE-2024-51665. Magical Addons For Elementor <= 1.2.1 - Authenticated (Subscriber+) Server-Side Request Forgery

1