Nxploit
37 exploits
Active since Jan 2024
Newscrunch <= 1.8.4 - Cross-Site Request Forgery via newscrunch_install_and_activate_plugin()
NgocCode WP Load Gallery <2.1.6 - RCE
WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal via wfu_file_downloader.php
Newscrunch <= 1.8.4.1 - Authenticated Arbitrary File Upload via newscrunch_install_and_activate_plugin
The Novel Design Store Directory <4.3.0 - Unrestricted Upload of Fi...
Picsmize <= 1.0.0 - Unauthenticated Arbitrary File Upload
WordPress Really Simple SSL Plugin Authentication Bypass to RCE
MetricThemes Munk Sites <1.0.8 - CSRF
Cliconomics Exclusive Content Password Protect - CSRF
Order Attachments for WooCommerce 2.0-2.4.1 - Authenticated Arbitrary File Upload via wcoa_add_attachment AJAX Action
Verbalize WP <= 1.0 - Unauthenticated Arbitrary File Upload
Webdeclic WPMasterToolKit <1.13.1 - Code Injection
nssTheme Wp NssUser Register <1.0.0 - Privilege Escalation
Web Directory Free <1.7.3 - Code Injection
Vayu Blocks - Unauthorized Plugin Installation
Top Store theme <1.5.4 - Privilege Escalation
SEO LAT Auto Post <= 2.2.1 - Unauthenticated File Overwrite and Remote Code Execution via remote_update AJAX Action
Arttia Creative Datasets Manager <1.5 - RCE
CVSS 10.0
WP REST API FNS <= 1.0.0 - Authentication Bypass
CVSS 9.8
WP Query Console <= 1.0 - Remote Code Execution
CVSS 10.0
Siddharth Nagar Import Export For WooCommerce <1.5 - RCE
CVSS 9.9
ThemeHunk Zita Site Builder <1.0.2 - Info Disclosure
CVSS 9.1
Beee ACF City Selector <1.14.0 - RCE
CVSS 6.6
PZ Frontend Manager < 1.0.6 - Cross-Site Request Forgery
CVSS 8.8
User Profile Builder <3.11.8 - Info Disclosure
CVSS 9.1