
WBW Product Table Pro <= 1.9.4 - Unauthenticated Arbitrary SQL Execution to RCE
CVE-2024-43918 The WBW Product Table Pro plugin for WordPress is vulnerable to unauthorized arbitrary SQL Execution due to a missing capability check on a function in all versions up to, and including, 1.9.4. This makes it possible for unauthenticated attackers to execute arbitrary SQL queries that can be used to steal sensitive data or gain elevated access to a vulnerable site.
For more wordpress exploits and exclusive ones contact me on telegram @KtN1990.
To run this exploit you need to have python 3 and websites list then execute
python3 exploit.py -l list.txt -t 100
