Login Register






Wordpress Vulnerability Searcher filter_list
Author
Message
Wordpress Vulnerability Searcher #1
This is a small script I wrote to get vulnerabilites using the wpvulndb API. You need to get your own key from their API page, https://wpvulndb.com/api The key in the script is one I used, it does not work now, it's for demo purposes.

Code:
#/bin/sh #sunjester key=aESBUbLBlkRXU3xfIzBuCJaBNcBwIrT63ixK265QGUI ver=$1 nver=`echo $1 |fold -w1 | paste -sd "."` curl -s -H "Authorization: Token token=$key" https://wpvulndb.com/api/v3/wordpresses/$ver >json cat json |jq -r '.["'$nver'"].vulnerabilities[].title' rm json

You can also download it in a zip file, https://anonfile.com/98ZfX2p0be/wpvdb_zip

Example usage for 4.9.2, 5.0, and 1.0 versions...

Code:
(xenial)root@localhost:/var/www/html/exploits# sudo sh wp.sh 492 WordPress <= 4.9.4 - Application Denial of Service (DoS) (unpatched) WordPress 3.7-4.9.4 - Remove localhost Default WordPress 3.7-4.9.4 - Use Safe Redirect for Login WordPress 3.7-4.9.4 - Escape Version in Generator Tag WordPress <= 4.9.6 - Authenticated Arbitrary File Deletion WordPress <= 5.0 - Authenticated File Delete WordPress <= 5.0 - Authenticated Post Type Bypass WordPress <= 5.0 - PHP Object Injection via Meta Data WordPress <= 5.0 - Authenticated Cross-Site Scripting (XSS) WordPress <= 5.0 - Cross-Site Scripting (XSS) that could affect plugins WordPress <= 5.0 - User Activation Screen Search Engine Indexing WordPress <= 5.0 - File Upload to XSS on Apache Web Servers

Code:
(xenial)root@localhost:/var/www/html/exploits# sudo sh wp.sh 50 WordPress <= 5.0 - Authenticated File Delete WordPress <= 5.0 - Authenticated Post Type Bypass WordPress <= 5.0 - PHP Object Injection via Meta Data WordPress <= 5.0 - Authenticated Cross-Site Scripting (XSS) WordPress <= 5.0 - Cross-Site Scripting (XSS) that could affect plugins WordPress <= 5.0 - User Activation Screen Search Engine Indexing WordPress <= 5.0 - File Upload to XSS on Apache Web Servers

Code:
(xenial)root@localhost:/var/www/html/exploits# sudo sh wp.sh 10 WordPress <= 4.9.4 - Application Denial of Service (DoS) (unpatched) WordPress <= 4.9.6 - Authenticated Arbitrary File Deletion

Demo video, https://asciinema.org/a/Zt9qnuY3OZHJRxkULrNrw0F3v
(This post was last modified: 01-08-2019, 01:18 AM by sunjester.)

[+] 3 users Like sunjester's post
Reply

RE: Wordpress Vulnerability Searcher #2
hmm nice thank you for info Smile
(>( G )<)

Reply

RE: Wordpress Vulnerability Searcher #3
ooooo thanks
tried. fire))

Reply

RE: Wordpress Vulnerability Searcher #4
thank you for posting this information.
My IT skills that I know perfect is SQL, HTML ,css ,wordpress, PHP.
coding skills that I know is Java, JavaScript and C#

Reply

RE: Wordpress Vulnerability Searcher #5
Excellent guide. Wordpress is a fun thing to fnuck with on all occasions.

Reply

RE: Wordpress Vulnerability Searcher #6
(03-28-2019, 06:44 PM)Kludge Wrote: Excellent guide. Wordpress is a fun thing to fnuck with on all occasions.

I agree.
My IT skills that I know perfect is SQL, HTML ,css ,wordpress, PHP.
coding skills that I know is Java, JavaScript and C#

Reply