PoC for CVE-2026-3891 — Unauthenticated Arbitrary File Upload leading to Remote Code Execution in Pix for WooCommerce <= 1.5.0
☆17Jul 20, 2026Updated this week
Alternatives and similar repositories for CVE-2026-3891-Pix-for-WooCommerce-Plugin-Exploit
Users that are interested in CVE-2026-3891-Pix-for-WooCommerce-Plugin-Exploit are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Burp Suite extension for cross-identity & cross-tenant access-control testing — BAC, IDOR, BOLA, and privilege escalation.☆43Jul 12, 2026Updated last week
- Fast Go-based XSS assessment toolkit☆20Mar 18, 2026Updated 4 months ago
- FortiSandbox RCE Scanner — CVE-2026-39808☆26Apr 21, 2026Updated 3 months ago
- Blind XSS SVG☆10Mar 27, 2023Updated 3 years ago
- ☆14Mar 6, 2025Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- ☆22Jul 7, 2026Updated 2 weeks ago
- Passive JavaScript reconnaissance for penetration testers — bridging Burp Suite traffic into structured, AST-based analysis in VSCode.☆36Feb 5, 2026Updated 5 months ago
- Apache (CVE-2025-24813) GOExploiter Checker & Exploiter very Fast☆20Oct 5, 2025Updated 9 months ago
- This tool serves as an initial version scanner specifically designed for PrestaShop, a popular e-commerce platform. The primary purpose o…☆20Jun 2, 2025Updated last year
- A bash script that extracts `shodan-query, google-query, censys-query, fofa-query, hunter-query, zoomeye-query` in nucleihub-templates.☆15Feb 17, 2026Updated 5 months ago
- Non-destructive detector + Docker lab for wp2shell (CVE-2026-63030 REST /batch/v1 route confusion + CVE-2026-60137 author__not_in SQLi) i…☆35Updated this week
- burpsuite extension to analyze javascript files using semgrep☆13Feb 3, 2025Updated last year
- FrontHunter is a tool for testing large lists of domains to identify candidates for domain fronting.☆22May 5, 2025Updated last year
- SSRFHunter☆18Jan 17, 2026Updated 6 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A comprehensive WordPress vulnerability scanner and exploitation framework for authorized penetration testing. This tool automatically de…☆72May 21, 2026Updated 2 months ago
- CVE-2026-63030, CVE-2026-60137, wp2shell scanner☆20Updated this week
- Nginx Rewrite CVE Scan(CVE-2026-42945 nginx-rift CVE-2026-9256)☆33May 27, 2026Updated last month
- ☆21May 7, 2026Updated 2 months ago
- Vite Arbitrary File Read Exploit☆15Jun 25, 2025Updated last year
- CVE-2026-21643☆18Mar 28, 2026Updated 3 months ago
- This lab is for **EDUCATIONAL PURPOSES ONLY**. Use it responsibly and only on systems you own or have explicit permission to test. Do not…☆21Feb 20, 2026Updated 5 months ago
- SelfHosted - Bug Bounty Programs | Discover new and fresh bug bounty programs across platforms. Updated frequently to always display the …☆16Nov 24, 2025Updated 7 months ago
- This repository contains all the GF-Patterns Repositories. All we have to do is just to run the given Shell File and it's Done !!☆21Jun 28, 2025Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- parse ffuf & map endpoints to wordlists☆21Feb 25, 2021Updated 5 years ago
- C++ notes☆12Jun 12, 2026Updated last month
- ☆50Feb 27, 2026Updated 4 months ago
- Detection template for CVE-2025-8110☆22Dec 11, 2025Updated 7 months ago
- Demonstrate how a signed driver can bypass defenses to deploy ransomware on Windows 11 with advanced AV and UAC evasion techniques.☆32Updated this week
- ☆42Mar 12, 2025Updated last year
- Stock vulnerable wordpress RCE poc for wp2shell.☆91Updated this week
- A powerful Bash script for extracting URLs and API endpoints from HTML, JavaScript, and JSON content of web pages. Designed for security …☆18Jun 23, 2026Updated last month
- Kernel Information Disclosure☆35Jan 13, 2026Updated 6 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Burp Suite extension — passively detects secrets, API keys, credentials, JWTs & PII in HTTP traffic. 160+ detection rules, bulk scan, ent…☆34May 15, 2026Updated 2 months ago
- My-custom-sensitive-info-disclsure-nuclei-template☆34Jan 3, 2026Updated 6 months ago
- Passively check for XSS character encodings☆20Mar 9, 2026Updated 4 months ago
- Automated Recon Tool Installer☆16Jun 29, 2022Updated 4 years ago
- It serves as a practical guide for security researchers to identify and test WordPress targets effectively during bug bounty hunting.☆27Updated this week
- Burpsuite Extension for Jsmon☆25Jul 1, 2026Updated 3 weeks ago
- Tool for fetching all the available waybackmachine snapshot urls☆26Oct 8, 2024Updated last year