commit
8ac2595eff
|
@ -13,6 +13,7 @@ info:
|
|||
|
||||
Source/References:
|
||||
- https://github.com/GeneralEG/CVE-2019-15858
|
||||
tags: wordpress,wp-pluing
|
||||
|
||||
requests:
|
||||
- method: GET
|
||||
|
|
|
@ -5,6 +5,7 @@ info:
|
|||
author: randomrobbie
|
||||
severity: high
|
||||
description: W3 Total Cache 0.9.2.6-0.9.3 - Unauthenticated Arbitrary File Read / SSRF
|
||||
tags: wordpress,wp-pluing,ssrf
|
||||
|
||||
requests:
|
||||
- raw:
|
||||
|
|
|
@ -4,6 +4,7 @@ info:
|
|||
name: WordPress social-warfare RFI
|
||||
author: madrobot & dwisiswant0
|
||||
severity: critical
|
||||
tags: wordpress,wp-pluing,ssrf
|
||||
|
||||
# Reference:- https://github.com/mpgn/CVE-2019-9978
|
||||
|
||||
|
|
|
@ -5,6 +5,7 @@ info:
|
|||
author: PR3R00T
|
||||
severity: high
|
||||
reference: "https://blog.nintechnet.com/wordpress-easy-wp-smtp-plugin-fixed-zero-day-vulnerability/"
|
||||
tags: wordpress,wp-pluing
|
||||
|
||||
requests:
|
||||
- method: GET
|
||||
|
|
|
@ -5,7 +5,7 @@ info:
|
|||
author: Random-Robbie
|
||||
severity: medium
|
||||
description: Sassy Social Share <= 3.3.3 - Cross-Site Scripting (XSS)
|
||||
|
||||
tags: wordpress,wp-pluing
|
||||
requests:
|
||||
- method: GET
|
||||
path:
|
||||
|
|
|
@ -3,6 +3,7 @@ info:
|
|||
name: Wordpress W3C Total Cache SSRF <= 0.9.4
|
||||
author: random-robbie
|
||||
severity: medium
|
||||
tags: wordpress,wp-pluing
|
||||
|
||||
# Reference
|
||||
# https://wpvulndb.com/vulnerabilities/8644
|
||||
|
|
|
@ -3,6 +3,8 @@ info:
|
|||
name: WordPress accessible wp-config
|
||||
author: Kiblyn11 & zomsop82 & madrobot & geeknik
|
||||
severity: high
|
||||
tags: wordpress,backups
|
||||
|
||||
requests:
|
||||
- method: GET
|
||||
path:
|
||||
|
|
|
@ -4,6 +4,7 @@ info:
|
|||
name: WordPress DB Backup
|
||||
author: dwisiswant0
|
||||
severity: medium
|
||||
tags: wordpress,backups
|
||||
|
||||
requests:
|
||||
- method: GET
|
||||
|
|
|
@ -4,6 +4,7 @@ info:
|
|||
name: WordPress debug log
|
||||
author: geraldino2 & @dwisiswant0
|
||||
severity: low
|
||||
tags: wordpress,logs
|
||||
|
||||
requests:
|
||||
- method: GET
|
||||
|
|
|
@ -4,6 +4,7 @@ info:
|
|||
name: Wordpress directory listing
|
||||
author: Manas_Harsh
|
||||
severity: info
|
||||
tags: wordpress
|
||||
|
||||
requests:
|
||||
- method: GET
|
||||
|
|
|
@ -3,7 +3,7 @@ info:
|
|||
name: wordpress-emails-verification-for-woocommerce
|
||||
author: random-robbie
|
||||
severity: critical
|
||||
|
||||
tags: wordpress,wp-pluing
|
||||
|
||||
# Email Verification for WooCommerce < 1.8.2 - Loose Comparison to Authentication Bypass
|
||||
# https://wpvulndb.com/vulnerabilities/10318
|
||||
|
|
|
@ -4,6 +4,7 @@ info:
|
|||
name: WordPress Emergency Script
|
||||
author: dwisiswant0
|
||||
severity: info
|
||||
tags: wordpress
|
||||
|
||||
# Ref:-
|
||||
# https://wordpress.org/support/article/resetting-your-password/#using-the-emergency-password-reset-script
|
||||
|
|
|
@ -4,6 +4,7 @@ info:
|
|||
name: WordPress Installer Log
|
||||
author: dwisiswant0
|
||||
severity: info
|
||||
tags: wordpress,logs
|
||||
|
||||
requests:
|
||||
- method: GET
|
||||
|
|
|
@ -4,6 +4,7 @@ info:
|
|||
name: Social Metrics Tracker <= 1.6.8 - Unauthorised Data Export
|
||||
author: randomrobbie
|
||||
severity: medium
|
||||
tags: wordpress,wp-pluing
|
||||
|
||||
requests:
|
||||
- method: GET
|
||||
|
|
|
@ -4,6 +4,7 @@ info:
|
|||
name: WordPress ThemeMarkers DB Migration File
|
||||
author: dwisiswant0
|
||||
severity: info
|
||||
tags: wordpress,wp-pluing,backups
|
||||
|
||||
requests:
|
||||
- method: GET
|
||||
|
|
|
@ -4,6 +4,7 @@ info:
|
|||
name: Wordpress user enumeration
|
||||
author: Manas_Harsh
|
||||
severity: info
|
||||
tags: wordpress
|
||||
|
||||
requests:
|
||||
- method: GET
|
||||
|
|
|
@ -4,6 +4,7 @@ info:
|
|||
name: WordPress Wordfence 7.4.6 Cross Site Scripting
|
||||
author: madrobot
|
||||
severity: medium
|
||||
tags: wordpress,wp-pluing,xss
|
||||
|
||||
requests:
|
||||
- method: GET
|
||||
|
|
|
@ -5,6 +5,7 @@ info:
|
|||
author: dwisiswant0
|
||||
severity: high
|
||||
description: Critical Information Disclosure on WP Courses plugin < 2.0.29 exposes private course videos and materials
|
||||
tags: wordpress,wp-pluing
|
||||
|
||||
# References:
|
||||
# - [1] https://www.exploit-db.com/exploits/48910
|
||||
|
|
|
@ -4,6 +4,7 @@ info:
|
|||
name: WordPress user registration enabled
|
||||
author: Ratnadip Gajbhiye
|
||||
severity: info
|
||||
tags: wordpress
|
||||
|
||||
requests:
|
||||
- method: GET
|
||||
|
|
|
@ -4,6 +4,7 @@ info:
|
|||
name: WordPress xmlrpc
|
||||
author: udit_thakkur
|
||||
severity: info
|
||||
tags: wordpress
|
||||
|
||||
requests:
|
||||
- method: GET
|
||||
|
|
Loading…
Reference in New Issue