From a00eb6c922b56cd1a8d858f03b03055b824f023e Mon Sep 17 00:00:00 2001 From: Rainyseason <73454853+Rainyseason-c@users.noreply.github.com> Date: Mon, 7 Apr 2025 14:16:51 +0800 Subject: [PATCH] =?UTF-8?q?Update=20WordPress=20RomethemeKit=20Plugin?= =?UTF-8?q?=E5=AD=98=E5=9C=A8RCE=E6=BC=8F=E6=B4=9E(CVE-2025-30911).md?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- ...ordPress RomethemeKit Plugin存在RCE漏洞(CVE-2025-30911).md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/wpoc/WordPress/WordPress RomethemeKit Plugin存在RCE漏洞(CVE-2025-30911).md b/wpoc/WordPress/WordPress RomethemeKit Plugin存在RCE漏洞(CVE-2025-30911).md index fa6c4b8..23435bf 100644 --- a/wpoc/WordPress/WordPress RomethemeKit Plugin存在RCE漏洞(CVE-2025-30911).md +++ b/wpoc/WordPress/WordPress RomethemeKit Plugin存在RCE漏洞(CVE-2025-30911).md @@ -3,6 +3,10 @@ ## 漏洞描述 该漏洞允许经过身份验证的攻击者(具有管理员权限)以编程方式安装和激活任何插件(包括潜在的恶意插件),这可能导致在服务器上完全执行代码。 +## fofa +``` +"/wp-content/plugins/RomethemeKit" +``` ## poc ```javascript import requests