wp-plugin-cve-hunt

Installation
SKILL.md

WP-PLUGIN-CVE-HUNT — Systematic WordPress Plugin CVE Discovery & Exploitation

When to Use

Use after WordPress detection recon has identified a list of WP targets with known plugins. This skill goes beyond simple readme.txt version checking — it performs multi-source version extraction, CVE database cross-referencing, version comparison, vulnerability assessment, and PoC generation. Ideal when you have a list of 10+ WP domains and need to systematically find which specific plugin CVEs are exploitable.

Distinction from wp-plugin-automation: this skill focuses on the human-guided CVE research process — WPScan API integration, Patchstack database queries, NVD cross-referencing, CVE detail investigation, and manual PoC validation. wp-plugin-automation handles the batch scanning pipeline across hundreds of domains.

Quick Reference

# Quick CVE scan for a single target
TARGET="example.com"

# 1. List plugins via readme.txt
for p in elementskit revslider elementor woocommerce gravityforms jetpack wp-file-manager wordpress-seo give contact-form-7; do
  v=$(curl --max-time 30 --connect-timeout 10 -sk "https://$TARGET/wp-content/plugins/$p/readme.txt" 2>/dev/null | grep -i "stable tag\|version" | head -1)
  [ -n "$v" ] && echo "PLUGIN: $p -> $v"
done
Installs
11
GitHub Stars
1.2K
First Seen
Jul 9, 2026
wp-plugin-cve-hunt — uphiago/recon-skills