Nxploited
156 exploits
Active since Nov 2023
SoftClever Limited Sync Posts <1.0 - RCE
Quentn WP <1.2.8 - Privilege Escalation
WPFactory Custom CSS, JS & PHP <2.4.1 - CSRF
MetricThemes Munk Sites <1.0.8 - CSRF
WP-Advanced-Search <3.3.9.3 - Code Injection
NiteoThemes CMP - Unrestricted Upload
JAY Login & Register <2.4.01 - Auth Bypass
Fox LMS - WordPress LMS Plugin <1.0.5.1 - Privilege Escalation
ThemeEgg ToolKit <= 1.2.9 - Arbitrary File Upload
Webful Creations Computer Repair Shop <3.8115 - RCE
Scott Paterson ScottCart <= 1.1 - Remote Code Execution
Verbalize WP <= 1.0 - Unauthenticated Arbitrary File Upload
Order Attachments for WooCommerce 2.0-2.4.1 - Authenticated Arbitrary File Upload via wcoa_add_attachment AJAX Action
Time Clock and Time Clock Pro <= 1.2.2 - Unauthenticated Remote Code Execution via etimeclockwp_load_function_callback
GutenKit < 2.1.0 - Unauthenticated Arbitrary File Upload via install-active-plugin Endpoint
Webdeclic WPMasterToolKit <1.13.1 - Code Injection
nssTheme Wp NssUser Register <1.0.0 - Privilege Escalation
Cliconomics Exclusive Content Password Protect - CSRF
Web Directory Free <1.7.3 - Code Injection
XLPlugins Finale Lite < 2.18.0 - Unauthenticated Arbitrary Plugin Installation and Activation
SEO LAT Auto Post <= 2.2.1 - Unauthenticated File Overwrite and Remote Code Execution via remote_update AJAX Action
Vayu Blocks - Unauthorized Plugin Installation
Top Store theme <1.5.4 - Privilege Escalation
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
CVSS 10.0
WordPress Woocommerce Wholesale Lead Capture plugin <= 2.0.3.1 - Arbitrary File Upload vulnerability
CVSS 9.0