WPAUDIT: Advanced WordPress security auditing suite & vulnerability scanner. Automates pentesting with Nmap, WPScan, Nuclei, SQLMap. Comprehensive reports. Ideal for ethical hackers & Kali Linux.
-
Updated
May 27, 2025 - Python
WPAUDIT: Advanced WordPress security auditing suite & vulnerability scanner. Automates pentesting with Nmap, WPScan, Nuclei, SQLMap. Comprehensive reports. Ideal for ethical hackers & Kali Linux.
#1 Open WordPress vulnerability database tracking 27,000+ issues (plugins, themes, core). Updated On Daily Basis. Formats: SQLite, CSV, Excel.
CVE-2026-87902 – WordPress Core LFI→RCE Toolkit (CVSS 9.2) - Red/Blue Team suite for WordPress 4.7–7.1.1. | 2 tools: Full Exploit (LFI, PEAR RCE, admin create, webshell, reverse shell, loot, mass scan, stealth) & SafeChecker (version detect, risk audit, JSON report). Use Ethically & Authorized Enviorement, Stay Legal <3
Wordpress CVE-2023-32243
Wordpress Default Password
Wordpress CVE-2023-34960
A lightweight directory/file scanner using custom payloads (inurl, filetype, intitle, etc.) for security testing on authorized targets.
The tool targets WordPress websites that use the Super Backup & Clone plugin and are vulnerable to arbitrary file upload.
Non-intrusive checker for CVE-2026-63030 / CVE-2026-60137 ("wp2shell"), a pre-authentication RCE chain in WordPress core.
Hands-on exploit lab for CVE-2024-28000 — unauthenticated privilege escalation in LiteSpeed Cache (WordPress plugin, <=6.3.0.1). Spins up a vulnerable environment with Docker and includes a Go-based brute-forcer that cracks the weak mt_rand hash to create an administrator account.
To associate your repository with the wordpress-vulnerability topic, visit your repo's landing page and select "manage topics."