2021-07-28 17:56:40 +08:00
..
2021-07-28 17:56:40 +08:00

WordPress Plugin Mailpress 4.5.2 RCE

In the WordPress Mailpress Plugin, the subject parameter in the iview function in the mailpress/mp-includes/class/MP_Actions.class.php file is not filtered, and pass to do_eval function, leading to remote code execution.

Affected version: WordPress Plugin Mailpress <= 4.5.2

FOFA query rule: app="WordPress"

Demo