
Il plugin non impedisce ad attaccanti non autenticati di sovrascrivere variabili locali durante il rendering dei template tramite l'API REST, il che può portare ad attacchi di Local File Inclusion.
Il plugin non impedisce ad attaccanti non autenticati di sovrascrivere variabili locali durante il rendering dei template tramite REST API, il che può portare ad attacchi di Local File Inclusion.
usage: PoC.py [-h] -u URL [-p PAYLOAD]
Essential Blocks < 4.4.3 - Unauthenticated Local File Inclusion
options:
-h, --help show this help message and exit
-u URL, --url URL Target WordPress site URL (e.g., http://192.168.100.74:888/wordpress)
-p PAYLOAD, --payload PAYLOAD
File to read (default: /etc/passwd)