07-28-2024, 03:33 AM
okay, try this to see if works
|
new wordpress website takeover vuln (video + poc )
by zinzeur - Sunday January 14, 2024 at 04:28 PM
|
|
07-28-2024, 03:33 AM
okay, try this to see if works
08-02-2024, 04:03 PM
yo am i late? is it already patched/fixed? someone tell me hhhh
![]() btw great great share mate im gonna check myself if it still work
08-02-2024, 10:09 PM
Nice info. interest it
08-02-2024, 10:20 PM
Need to check this, thank you.
08-04-2024, 02:04 PM
Thank you gonna test this later !
08-05-2024, 04:46 PM
thanks lets check this
08-05-2024, 09:34 PM
thank you so much
Ban reason: Leeching | http://raiddfzn73ir6iyxlf7nwytnujiflddog...an-Appeals if you feel this is incorrect. (Permanent)
08-06-2024, 06:53 PM
Thanks for the share, lovu you
08-07-2024, 09:57 AM
i want see this
08-07-2024, 02:19 PM
(01-14-2024, 04:28 PM)zinzeur Wrote: This is a brand new vuln (released about 3 days ago) affecting wordpress websites (any version) with post smtp plugin installed version <=2.8.7 (latest is 2.8.9). It allows complete admin takeover by ressetting password and retrieving sent email from smtp log api . Enjoy !! Thank you for providing the poc |
|
« Next Oldest | Next Newest »
|
| Possibly Related Threads… | |||||
| Thread | Author | Replies | Views | Last Post | |
| [POC] Google OAuth "MultiLogin" endpoint 0-day | 106 | 13,228 |
02-10-2026, 03:34 PM Last Post: |
||
| Cool Remote Patching ETW/Amsi PoC | 6 | 2,098 |
02-08-2026, 07:58 AM Last Post: |
||
| CVE-2025-40554 - SolarWinds Web Help Desk Auth Bypass & RCE PoC | 3 | 79 |
02-07-2026, 03:32 PM Last Post: |
||
| POC CVE-2025-24071 | 15 | 810 |
02-07-2026, 08:53 AM Last Post: |
||
| WordPress LFI to RCE - CVE-2025-0366 | 1 | 463 |
02-05-2026, 09:53 AM Last Post: |
||