Skip to content

mhelwig/wp-webshell-xss

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 
 
 

Repository files navigation

wp-webshell-xss

A simple wordpress webshell injector

This is an attack script to insert a simple webshell in a file of the wordpress plugin "Event Register" by making use of the Wordpress Plugin Editor feature.

It can be injected via a persistent XSS in the attendee's list.

Probably also useful with other persistent XSS vulnerabilities, though you would have to adapt the URLs to inject into another file.

About

A simple wordpress webshell injector

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published