Nxploited
156 exploits
Active since Nov 2023
StoryChief <= 1.0.42 - Unauthenticated Arbitrary File Upload via Webhook REST-API Endpoint
CVSS 9.8
Appy Pie Connect <1.1.2 - Privilege Escalation
CVSS 9.8
AdForest theme <6.0.9 - Auth Bypass
CVSS 9.8
RestroPress 3.0.0-3.1.9.2 - Unauthenticated Authentication Bypass via REST API
CVSS 9.8
StoreKeeper <14.4.4 - Unrestricted Upload
CVSS 10.0
BeyondCart Connector <2.1.0 - Privilege Escalation
CVSS 9.8
WPvivid Backup & Migration < 0.9.116 - Authenticated Arbitrary File Upload via wpvivid_upload_import_files
CVSS 7.2
Alone - Charity Multipurpose Non-profit WordPress Theme <7.8.3 - RCE
CVSS 9.8
Miraculous Core Plugin <2.0.7 - Privilege Escalation
CVSS 9.8
PT Project Notebooks 1.0.0-1.1.3 - Unauthenticated Privilege Escalation via wpnb_pto_new_users_add()
CVSS 9.8
Rometheme RomethemeKit For Elementor <1.5.4 - Code Injection
CVSS 9.9
SoJ SoundSlides <= 1.2.2 - Authenticated Arbitrary File Upload via soj_soundslides_options_subpanel()
CVSS 8.8
Motors Plugin <= 1.4.64 - Authenticated Arbitrary Plugin Installation
CVSS 8.8
Celestial Aura < 2.2 - Unrestricted Upload of File with Dangerous Type
CVSS 9.9
Nirmal Kumar Ram WP Remote Thumbnail <1.3.1 - RCE
CVSS 9.9
Buddypress Humanity <= 1.2 - Cross-Site Request Forgery
CVSS 9.8
KiotViet Sync <= 1.8.5 - Unauthenticated Arbitrary File Upload via create_media() Function
CVSS 9.8
WP Directory Kit <= 1.4.4 - Unauthenticated Authentication Bypass via Weak Auto-Login Token
CVSS 10.0
Crowdytheme Arolax < 1.7 - Missing Authorization
CVSS 8.8
RomanCode MapSVG Lite <8.5.34 - RCE
CVSS 9.9
Anant Addons for Elementor <1.1.5 - CSRF
CVSS 9.6
PZ Frontend Manager < 1.0.6 - Cross-Site Request Forgery
CVSS 8.8
PDF Generator Addon - Path Traversal
CVSS 7.5
WatchTowerHQ <= 3.10.1 - Unauthenticated Authentication Bypass via Empty OTA Token
CVSS 9.8
Wux Blog Editor <3.0.0 - File Upload
CVSS 9.8