new wordpress website takeover vuln (video + poc )
by zinzeur - Sunday January 14, 2024 at 04:28 PM
Thanks you brother
Reply
thanks sir, hope you have a good day, anyways thanks for sharing
Reply
nice threads... i hope that's working
Reply
thanks you bro for sharing
Reply
Thanks i'll check it now
Reply
[citation="zinzeur" pid='352841' dateline='1705249732']
Il s'agit d'une toute nouvelle vulnérabilité (publiée il y a environ 3 jours) affectant les sites Web WordPress (toutes versions) avec la version installée du plugin post smtp <= 2.8.7 (la dernière est 2.8.9). Il permet une prise de contrôle complète de l'administrateur en réinitialisant le mot de passe et en récupérant les e-mails envoyés à partir de l'API du journal smtp. Amusez-vous bien !!
ps: La vidéo est à moi
vidéo :
Apprécier
[/citation]
Reply
wow that perfect
Reply
Nice info. Check it.
Reply
thank you so much
Reply
thank you so much
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [POC] Google OAuth "MultiLogin" endpoint 0-day Farfallaiero 106 13,230 02-10-2026, 03:34 PM
Last Post: birhikayemvar
  Cool Remote Patching ETW/Amsi PoC pepeloco 6 2,098 02-08-2026, 07:58 AM
Last Post: zeroday99
  CVE-2025-40554 - SolarWinds Web Help Desk Auth Bypass & RCE PoC miyako 3 79 02-07-2026, 03:32 PM
Last Post: cysc
  POC CVE-2025-24071 caca28sapo1 15 810 02-07-2026, 08:53 AM
Last Post: hacker0123
  WordPress LFI to RCE - CVE-2025-0366 Serious 1 463 02-05-2026, 09:53 AM
Last Post: Sammm89



 Users browsing this thread: 1 Guest(s)