
CVE-2024-4439 docker and poc
CVE-2024-4439 docker and poc
After starting the Docker container, some additional configuration is needed. Visit 127.0.0.1:8080, complete the configuration,
In the backend – Appearance – Themes, select a theme, customize it, and configure.

Go to Design – Templates – Single Post


Select the avatar on the right, enter the theme editor.

First click the avatar, then click Settings in the top right. On the right, there are two options: 'Link to user profile' and 'Open in new window'. Check both buttons.
After publishing any article, you can leave a comment. In the comment, replace the author name with an XSS malicious payload.
" onmouseover="alert(1)"

CVE-2024-4439 WordPress XSS Stored Vulnerability Reproduction - Knownsec Community (aliyun.com)