Khaled Alenazi (Nxploited)
23 exploits
Active since Apr 2025
Cloudflare Image Resizing <1.5.6 - RCE
HT Contact Form Widget <= 2.2.1 - Unauthenticated Arbitrary File Upload
WordPress TNC Toolbox: Web Performance <1.4.2 - Info Disclosure
WordPress AI Engine Plugin MCP Unauthenticated Admin Creation to RCE
Flex QR Code Generator <1.2.5 - File Upload
Alone - Charity Multipurpose Non-profit WordPress Theme <7.8.3 - RCE
WordPress CSV Mass Importer <1.2 - Privilege Escalation
HyperComments <1.2.2 - Privilege Escalation
Profitori WordPress <2.1.1.3 - Privilege Escalation
Holest Engineering Spreadsheet Price Changer <2.4.37 - Privilege Es...
WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload via image_upload_handle Function
WP-Advanced-Search <3.3.9.3 - Code Injection
Appy Pie Connect <1.1.2 - Privilege Escalation
CVSS 9.8
BeyondCart Connector <2.1.0 - Privilege Escalation
CVSS 9.8
Concrete CMS < 8.5.21 and 9.0.0-9.4.2 - Reflected Cross-Site Scripting in Conversation Messages Dashboard Page
CVSS 4.8
Miraculous Core Plugin <2.0.7 - Privilege Escalation
CVSS 9.8
WPvivid Backup & Migration < 0.9.116 - Authenticated Arbitrary File Upload via wpvivid_upload_import_files
CVSS 7.2
PT Project Notebooks 1.0.0-1.1.3 - Unauthenticated Privilege Escalation via wpnb_pto_new_users_add()
CVSS 9.8
KiotViet Sync <= 1.8.5 - Unauthenticated Arbitrary File Upload via create_media() Function
CVSS 9.8
Celestial Aura < 2.2 - Unrestricted Upload of File with Dangerous Type
CVSS 9.9
SureTriggers - All-in-One Automation Platform < 1.0.78 - Authentication Bypass
CVSS 8.1
WordPress AI Engine Plugin MCP Unauthenticated Admin Creation to RCE
CVSS 9.8
OttoKit < 1.0.83 - SureTriggers allows Privilege Escalation
CVSS 9.8