{"repo":"AiGptCode/AiGPT-WordPress-Exploitation-Framework","free":true,"listed":false,"github":"https://github.com/AiGptCode/AiGPT-WordPress-Exploitation-Framework","clone":"git clone https://github.com/AiGptCode/AiGPT-WordPress-Exploitation-Framework.git","description":"AiGPT started from the concept of CVE‑2024‑27956 , the WP Automatic CSV injection — but has been completely rebuilt into a multi‑vector, unauthenticated WordPress exploitation engine. It now chains 13 real‑world CVEs to create an administrator account or drop a web shell directly, then automatically injects a reverse shell into the active theme","language":"Python","stars":132,"topics":["backdoor","backdoors","cve","hack","html","php","ransomware","reverse-shell","shell","website"],"license":null,"category":"cli-tools","readme_excerpt":"AiGPT — Automated WordPress Exploitation Framework AiGPT is a multi‑vector exploitation tool that automates the discovery and compromise of vulnerable WordPress sites. It fingerprints installed plugins, intelligently selects the best exploit, and delivers a reverse shell — often without needing any prior authentication. Thirteen unauthenticated CVEs are chained into a single, high‑performance framework designed for authorised penetration testing and security research. --- 🔥 Features - Multi‑vector engine — 13 distinct exploit paths in one tool - Zero‑auth admin creation — creates a WordPress administrator on 7 different vulnerable plugins - Token / session hijacking — steals API tokens or hijacks sessions to gain admin access - Direct SQL execution — inserts an admin user via raw SQL injection - Direct file upload — bypasses the entire login chain and drops a web shell instantly - Smart plugin fingerprinting — parallel probe of 12 plugins to choose the optimal attack - Priority‑based vector selection — confirmed vulnerable plugins are attacked first - Universal theme‑editor shell — after admin login, injects a reverse shell into the active theme - CIDR subnet scanning — finds WordPress installations across entire network ranges - Multi‑threaded — configurable worker count with adaptive delays - Clean logging — console + file output with timestamps - Graceful fallback — non‑WordPress targets are silently skipped --- 📦 Exploited Vulnerabilities (CVEs) CVE Plugin Type CVSS :--","default_branch":null,"files":null,"tree":[],"storefront":"/r/AiGptCode","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/AiGptCode/AiGPT-WordPress-Exploitation-Framework/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}