This is your work, valued
The UK guy working at BishopFox who seems to have far too many wordpress exploits
CVE-2023-32243. CVE-2023-32243 - Essential Addons for Elementor 5.4.0-5.7.1 - Unauthenticated Privilege Escalation
85grafana-ssrf. Authenticated SSRF in Grafana
83marshalsec-jar. marshalsec-0.0.3-SNAPSHOT-all compiled on X64
82CVE-2023-2982. WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) <= 7.6.4 - Authentication Bypass
81CVE-2023-7028. CVE-2023-7028
58phpunit-brute. Tool to try multiple paths for PHPunit RCE CVE-2017-9841
30wordpress-plugin-list. Wordpress Plugins List for Bruteforcing.
24nuclei-drupal-sa. Nuclei templates for drupal vulns... far from perfect
18service-now. Service-Now Article Bruteforcer
16wp-file-manager. wp-file-manager RCE
9CVE-2024-9593. Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code Execution
8CVE-2023-32117. Integrate Google Drive <= 1.1.99 - Missing Authorization via REST API Endpoints
6CVE-2024-49328. WP REST API FNS <= 1.0.0 - Privilege Escalation
6kong-pwn. Use Exposed KongAPI to act like a proxy and get metadata urls or internal urls
6CVE-2023-2732. MStore API <= 3.9.2 - Authentication Bypass
6super-secret-finder. Burp Plugin for Secret Matching
6CVE-2023-5204. AI ChatBot <= 4.8.9 - Unauthenticated SQL Injection via qc_wpbo_search_response
5redash-reset. Python
5CVE-2023-5412. Image horizontal reel scroll slideshow <= 13.2 - Authenticated (Subscriber+) SQL Injection via Shortcode
5coldfusion-amf. Coldfusion AMF PWN
5CVE-2022-0952. Sitemap by click5 < 1.0.36 - Unauthenticated Arbitrary Options Update
5CVE-2024-22145. InstaWP Connect <= 0.1.0.8 - Missing Authorization to Arbitrary Options Update (Subscriber+)
4CVE-2024-10924. Really Simple Security (Free, Pro, and Pro Multisite) 9.0.0 – 9.1.1.1 – Authentication Bypass
4Log4J-Exploits. Log4J Exploits for Different Systems
4CVE-2024-9796. WordPress WP-Advanced-Search <= 3.3.9 - Unauthenticated SQL Injection
4simple-file-list-rce. Simple File List < 4.2.3 - Unauthenticated Arbitrary File Upload RCE
4CVE-2024-9932. Wux Blog Editor <= 3.0.0 - Unauthenticated Arbitrary File Upload
3CVE-2024-9061. WP Popup Builder – Popup Forms and Marketing Lead Generation <= 1.3.5 - Unauthenticated Arbitrary Shortcode Execution via wp_ajax_nopriv_shortcode_Api_Add
3wordpress-exploits. Random Wordpres Exploits May or May Not Work.
3wordpress-php-object-helper. Know a plugin has a php object exploit but need to find which lib to use?
3CVE-2024-50498. WP Query Console <= 1.0 - Unauthenticated Remote Code Execution
3CVE-2023-47840. Qode Essential Addons <= 1.5.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation
3CVE-2024-6624. JSON API User <= 3.9.3 - Unauthenticated Privilege Escalation
3CVE-2022-3904. CVE-2022-3904 MonsterInsights < 8.9.1 - Stored Cross-Site Scripting via Google Analytics
3CVE-2024-49681. WP Sessions Time Monitoring Full Automatic <= 1.0.9 - Unauthenticated SQL Injection
3CVE-2024-0679. ColorMag <= 3.1.2 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation
2CVE-2024-12025. Collapsing Categories <= 3.0.8 - Unauthenticated SQL Injection
2woo. Exploit woocommerce SQLI and grab user and password hash
2csp-log4j. Finds CSP report urls and tests to see if they are vulnerable to log4j
2CVE-2024-9935. PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Unauthenticated Arbitrary File Download
2Rogue-MySql-Server. MySQL fake server for read files of connected clients
2what-wordpress. Tool to extract all themes and plugins that are shown on the front page of a wordpress site.
2dom-brute. Domain TLD prefix finder / 3rd party hosted.
2CVE-2023-2877. Formidable Forms < 6.3.1 - Subscriber+ Remote Code Execution
2CVE-2023-0630. CVE-2023-0630 - Slimstat Analytics < 4.9.3.3 - Subscriber+ SQL Injection
2CVE-2024-9234. GutenKit <= 2.1.0 - Unauthenticated Arbitrary File Upload
2SAP-brute. SAP Netweaver Login Bruteforcer.
2CVE-2024-50483. Meetup <= 0.1 - Authentication Bypass via Account Takeover
2CVE-2023-6700. Cookie Information | Free GDPR Consent Solution <= 2.0.22 - Authenticated (Subscriber+) Arbitrary Options Update
2CVE-2024-8529. LearnPress – WordPress LMS Plugin <= 4.2.7 - Unauthenticated SQL Injection via 'c_fields'
2CVE-2024-2387. Advanced Form Integration – Connect WooCommerce and Contact Form 7 to Google Sheets and other platforms <= 1.82.0 - SQL Injection to Reflected Cross-Site Scripting via integration_id
2CVE-2025-5701. HyperComments <= 1.2.2 - Unauthenticated (Subscriber+) Arbitrary Options Update
2django-bruteforce. Django Admin Url Bruteforce tool.
2CVE-2025-22954. Koha CVE-2025-22954: SQL Injection in lateissues-export.pl
2CVE-2024-13800. Popup Plugin For WordPress - ConvertPlus <= 3.5.30 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update
2CVE-2024-11423. Ultimate Gift Cards for WooCommerce <= 3.0.6 - Missing Authorization to Infinite Money Glitch
2CVE-2024-56064. WP SuperBackup <= 2.3.3 - Unauthenticated Arbitrary File Upload
2CVE-2024-55988. Navayan CSV Export <= 1.0.9 - Unauthenticated SQL Injection
2CVE-2024-12209. WP Umbrella: Update Backup Restore & Monitoring <= 2.17.0 - Unauthenticated Local File Inclusion
1CVE-2024-51665. Magical Addons For Elementor <= 1.2.1 - Authenticated (Subscriber+) Server-Side Request Forgery
1