Blogs
Priority
Extends > Themes "Helloworld" > Save
System > Backup > Content > Files > Save something
System > Settings > Maintenance Mode <?php phpinfo(); ?> ..Save
Plugins are often exploitable
searchsploit
github 'issues'
REF
DirbNiktoWP - Also has webapp/cms/scanner
Nibbleblog
Obtain Admin credentials > Activate My image plugin by visiting
Upload PHP shell, ignore warnings Visit
No matter what you NAME the php upload.. it will ALWAYS be "image.php" after uploading
Monstra
TartarHTB
Gym Management
REF: Redteam CTF Defcon Pivonka found this vuln on his own! Actually a pubic/known exploit
Last updated