
POC (RCE) -> CVE-2019-9978
Functional PoC for vulnerability CVE-2019-9978, affecting the plugin
Social Warfare <= 3.5.2, allowing Remote Code Execution (RCE) in WordPress.
This exploit abuses the swp_debug=load_options parameter to force the loading
of a remote payload, allowing command execution on the target server
and obtaining a reverse shell.
⚠️ Exclusive use for educational purposes and authorized environments.
nc)php-reverse-shell.php in the same directory as the scriptgit clone https://github.com/yup-Ivan/CVE-2019-9978.git
cd CVE-2019-9978
python3 CVE-2019-9978-POC.py