
Code and vulnerable WordPress container for exploiting CVE-2016-10033
This repository holds the necessary files to exploit CVE2016-10033 on a vulnerable version of WordPress.
With these instructions you will be able to get a reverse interactive shell (not Pseudo-TTY) in the container that is running the WordPress as the user that is running the Apache server.
This exploit does not require any type of authentication or plugin. Just plain WordPress code + Exim4 MTA to send emails from WordPress (installed in most servers).
admin as username