Nxploited
156 exploits
Active since Nov 2023
Hunk Companion <= 1.8.4 - Unauthenticated Arbitrary Plugin Installation and Activation via REST API
CVSS 9.8
Crafthemes Demo Import <3.3 - File Upload
CVSS 7.2
FileOrganizer - WordPress File Manager <= 1.0.9 - Authenticated Arbitrary File Upload via fileorganizer_ajax_handler
CVSS 7.5
Tainacan <= 0.21.7 - Authenticated Arbitrary File Read via Missing Authorization in get_file Function
CVSS 6.5
Grow by Tradedoubler <2.0.21 - Code Injection
CVSS 9.8
User Profile Builder <3.11.8 - Info Disclosure
CVSS 9.1
Beee ACF City Selector <1.14.0 - RCE
CVSS 6.6
Mike Leembruggen Simple Dashboard <2.0 - Privilege Escalation
CVSS 9.8
ThemeHunk Zita Site Builder <1.0.2 - Info Disclosure
CVSS 9.1
Siddharth Nagar Import Export For WooCommerce <1.5 - RCE
CVSS 9.9
Arttia Creative Datasets Manager <1.5 - RCE
CVSS 10.0
WP Query Console <= 1.0 - Remote Code Execution
CVSS 10.0
Portfolleo <= 1.2 - Unauthenticated Arbitrary File Upload
CVSS 9.9
WP REST API FNS <= 1.0.0 - Authentication Bypass
CVSS 9.8
biplob018 Shortcode Addons <3.2.5 - RCE
CVSS 9.1
WebsiteinWP Blogpoet <= 1.0.3 - Missing Authorization
CVSS 6.5
EventON WordPress Plugin < 2.2.7 - Unauthenticated Email Address Disclosure via AJAX Action
CVSS 5.3
Pubnews theme <1.0.7 - Privilege Escalation
CVSS 8.8
Debug Tool < 2.2 - Unauthenticated Arbitrary File Creation via dbt_pull_image()
CVSS 9.8
GPX Viewer <= 2.2.9 - Authenticated Arbitrary File Creation via gpxv_file_upload()
CVSS 8.8
Th Shop Mania <1.4.9 - Privilege Escalation
CVSS 8.8
Hunk Companion WP <1.9.0 - Auth Bypass
CVSS 9.8
Concrete CMS 9.0.0-9.2.4 - Stored Cross-Site Scripting via Role Name Field
CVSS 2.0
linkID WordPress <0.1.2 - Info Disclosure
CVSS 8.6
WP BASE Booking <4.9.2 - Info Disclosure
CVSS 6.5