PitchHut logo
CR4SH3R
A tool to exploit WordPress plugin vulnerabilities and extract database credentials
Pitch

CR4SH3R hunts Arbitrary File Download vulnerabilities in WordPress plugins and extracts database credentials — automatically

Description

CR4SH3R is a specialized vulnerability scanner designed to detect Arbitrary File Download flaws in WordPress plugins. It scans websites using a predefined set of paths to extract database credentials from wp-config.php. With fast, multi-threaded scanning and automatic data extraction, it provides an efficient and user-friendly solution for identifying critical vulnerabilities

Key Features

  • Multi-threaded Scanning: Perform rapid checks using concurrent requests to boost performance
  • Smart Data Extraction: Automatically identifies and parses database credentials and other sensitive values from wp-config.php
  • User-Friendly GUI: An intuitive interface that simplifies the scanning process for all skill levels
  • Structured Reporting: Export findings into clean Excel (XLSX) reports for easy documentation and analysis
  • Custom Payload Support: Easily extend detection capabilities by adding custom file paths or plugin-specific patterns

Future Features

  • Auto-Updater: Built-in version checker for seamless updates
  • Config Presets: Save and load frequently used scan configurations
  • Session History: Track previous scans with timestamps and results
  • Encrypted .env Storage: Prevent plaintext exposure when bundled into binaries

Contributions are encouraged to enhance CR4SH3R. Developers can fork the repository, create feature branches, and submit pull requests to collaborate on the project's evolution.

0 comments

No comments yet.

Sign in to be the first to comment.