
We access the WordPress web page where we will see that it has MFA enabled through the vulnerable plugin:

We must run the PoC and provide the login credentials:

Automatically, the browser will open via a temporary .html file within the administration panel.

To automatically deploy a vulnerable environment to recreate this scenario, you can use the following repository:
https://github.com/Trackflaw/CVE-2024-10924-Wordpress-Docker