CVE-2024-43998:Blogpoet 主题中存在授权缺失漏洞,允许访问未受 ACL 正确约束的功能。此问题影响 Blogpoet 版本从 n/a 到 1.0.3。
usage: CVE-2024-43998.py [-h] -u URL [-p PLUGIN]
CVE-2024-43998 exploit by Nxploited
options:
-h, --help show this help message and exit
-u URL, --url URL The base URL of the WordPress site, e.g., http://192.168.100.74:888
-p PLUGIN, --plugin PLUGIN
The plugin name to be installed and activated (default: wordpress-seo)
此脚本仅用于教育目的和经授权的安全评估。滥用此脚本可能会导致法律后果。在对任何系统进行测试之前,请务必获得适当的授权。