mirror of
https://github.com/0xMarcio/cve.git
synced 2025-11-30 18:56:19 +00:00
1.2 KiB
1.2 KiB
CVE-2021-24917
Description
The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.
POC
Reference
Github
- https://github.com/20142995/nuclei-templates
- https://github.com/ARPSyndicate/cve-scores
- https://github.com/ARPSyndicate/cvemon
- https://github.com/ARPSyndicate/kenzer-templates
- https://github.com/Cappricio-Securities/CVE-2021-24917
- https://github.com/D0rDa4aN919/D0rDa4aN919
- https://github.com/Whiteh4tWolf/pentest
- https://github.com/buildwithlian/CVE-2021-24917
- https://github.com/dikalasenjadatang/CVE-2021-24917
- https://github.com/soxoj/information-disclosure-writeups-and-pocs
- https://github.com/whattheslime/wps-show-login