mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 10:41:43 +00:00
24 lines
1.0 KiB
Markdown
24 lines
1.0 KiB
Markdown
![]() |
### [CVE-2022-4060](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-4060)
|
||
|

|
||
|

|
||
|
&color=brighgreen)
|
||
|
|
||
|
### Description
|
||
|
|
||
|
The User Post Gallery WordPress plugin through 2.19 does not limit what callback functions can be called by users, making it possible to any visitors to run code on sites running it.
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
- https://wpscan.com/vulnerability/8f982ebd-6fc5-452d-8280-42e027d01b1e
|
||
|
|
||
|
#### Github
|
||
|
- https://github.com/ARPSyndicate/cvemon
|
||
|
- https://github.com/ARPSyndicate/kenzer-templates
|
||
|
- https://github.com/cyllective/CVEs
|
||
|
- https://github.com/devmehedi101/wordpress-exploit
|
||
|
- https://github.com/im-hanzou/UPGer
|
||
|
- https://github.com/nomi-sec/PoC-in-GitHub
|
||
|
- https://github.com/securi3ytalent/wordpress-exploit
|
||
|
|