new wordpress website takeover vuln (video + poc )
by zinzeur - Sunday January 14, 2024 at 04:28 PM
okay, try this to see if works
Reply
yo am i late? is it already patched/fixed? someone tell me hhhh Sad  Angel
btw great great share mate im gonna check myself if it still work
Reply
Nice info. interest it
Reply
Need to check this, thank you.
Reply
Thank you gonna test this later !
Reply
thanks lets check this
Reply
thank you so much
Ban reason: Leeching | http://raiddfzn73ir6iyxlf7nwytnujiflddog...an-Appeals if you feel this is incorrect. (Permanent)
Reply
Thanks for the share, lovu you
Reply
i want see this
Reply
(01-14-2024, 04:28 PM)zinzeur Wrote: This is a brand new vuln (released about 3 days ago) affecting wordpress websites (any version) with post smtp plugin installed version <=2.8.7 (latest is 2.8.9). It allows complete admin takeover by ressetting password and retrieving sent email from smtp log api . Enjoy !!
ps: The video is mine
video :
Enjoy

Thank you for providing the poc
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [POC] Google OAuth "MultiLogin" endpoint 0-day Farfallaiero 106 13,228 02-10-2026, 03:34 PM
Last Post: birhikayemvar
  Cool Remote Patching ETW/Amsi PoC pepeloco 6 2,098 02-08-2026, 07:58 AM
Last Post: zeroday99
  CVE-2025-40554 - SolarWinds Web Help Desk Auth Bypass & RCE PoC miyako 3 79 02-07-2026, 03:32 PM
Last Post: cysc
  POC CVE-2025-24071 caca28sapo1 15 810 02-07-2026, 08:53 AM
Last Post: hacker0123
  WordPress LFI to RCE - CVE-2025-0366 Serious 1 463 02-05-2026, 09:53 AM
Last Post: Sammm89



 Users browsing this thread: 1 Guest(s)