
Proof-of-concept exploit per CVE-2024-6536, una XSS persistente autenticata nel plugin WordPress Zephyr Project Manager, che consente l'iniezione di script a livello di amministratore.
Questo script è una PoC per CVE-2024-6536, dove è possibile una XSS nel plugin Zephyr Project Manager per Wordpress. Richiede autenticazione e privilegi come amministratore del project manager.
python3 CVE-2024-6536.py -u <USERNAME> -p <PASSWORD> -w <url>
Esempio: python3 CVE-2024-6536.py -u user -p user -w http://localhost/wordpress