Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
PoC-CVE-2022-4939- — Proof-of-concept exploit for CVE-2022-4939, a WordPress plugin vulnerability allowing privilege escalation to administrator via crafted AJAX request. | Kitploit
Tools/GitHubGitHub/baconcricri/poc-cve-2022-4939-
Privilege EscalationVulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubbaconcricri/poc-cve-2022-4939-

PoC-CVE-2022-4939-

Proof-of-concept exploit for CVE-2022-4939, a WordPress plugin vulnerability allowing privilege escalation to administrator via crafted AJAX request.

View Repository
13 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

PoC-CVE-2022-4939

The attacker sends a specially crafted request to the wp_ajax_nopriv_wcfm_ajax_controller AJAX action to modify the membership registration form and set the registration role to that of an administrator. Then, the plugin processes the request and modifies the membership registration form to allow users to register with the role of an administrator. The attacker can register as a new user with the administrator role by submitting the modified membership registration form.

Download Tool