Nxploited
165 exploits
Active since Nov 2023
Nirmal Kumar Ram WP Remote Thumbnail <1.3.1 - RCE
CVSS 9.9
WP Directory Kit <= 1.4.4 - Unauthenticated Authentication Bypass via Weak Auto-Login Token
CVSS 10.0
KiotViet Sync <= 1.8.5 - Unauthenticated Arbitrary File Upload via create_media() Function
CVSS 9.8
Anant Addons for Elementor <1.1.5 - CSRF
CVSS 9.6
RomanCode MapSVG Lite <8.5.34 - RCE
CVSS 9.9
ThemeHunk Zita Site Builder <1.0.2 - Info Disclosure
CVSS 9.1
Beee ACF City Selector <1.14.0 - RCE
CVSS 6.6
PZ Frontend Manager < 1.0.6 - Cross-Site Request Forgery
CVSS 8.8
User Profile Builder <3.11.8 - Info Disclosure
CVSS 9.1
Grow by Tradedoubler <2.0.21 - Code Injection
CVSS 9.8
Tainacan <= 0.21.7 - Authenticated Arbitrary File Read via Missing Authorization in get_file Function
CVSS 6.5
PDF Generator Addon - Path Traversal
CVSS 7.5
FileOrganizer - WordPress File Manager <= 1.0.9 - Authenticated Arbitrary File Upload via fileorganizer_ajax_handler
CVSS 7.5
Crafthemes Demo Import <3.3 - File Upload
CVSS 7.2
Hunk Companion <= 1.8.4 - Unauthenticated Arbitrary Plugin Installation and Activation via REST API
CVSS 9.8
Wux Blog Editor <3.0.0 - File Upload
CVSS 9.8
WatchTowerHQ <= 3.10.1 - Unauthenticated Authentication Bypass via Empty OTA Token
CVSS 9.8
Siddharth Nagar Import Export For WooCommerce <1.5 - RCE
CVSS 9.9
Mike Leembruggen Simple Dashboard <2.0 - Privilege Escalation
CVSS 9.8
WP REST API FNS <= 1.0.0 - Authentication Bypass
CVSS 9.8
Portfolleo <= 1.2 - Unauthenticated Arbitrary File Upload
CVSS 9.9
WP Query Console <= 1.0 - Remote Code Execution
CVSS 10.0
Arttia Creative Datasets Manager <1.5 - RCE
CVSS 10.0
biplob018 Shortcode Addons <3.2.5 - RCE
CVSS 9.1
WebsiteinWP Blogpoet <= 1.0.3 - Missing Authorization
CVSS 6.5