
The tool targets WordPress websites that use the Super Backup & Clone plugin and are vulnerable to arbitrary file upload.

The tool targets WordPress websites that use the Super Backup & Clone plugin and are vulnerable to arbitrary file upload. It attempts to upload a malicious shell into the /wp-content/uploads/isnapshots/ directory. Once uploaded, the tool validates the existence of the shell and logs successful uploads into a shells.txt file.
shells.txt for easy reference.requests library installed:
pip install requests
python CVE-2024-9290.py
shells.txt.Disclaimer:
I have written the disclaimer on the cover of Jenderal92. You can check it HERE !!!