new wordpress website takeover vuln (video + poc )
by zinzeur - Sunday January 14, 2024 at 04:28 PM
#71
(Jan 14, 2024, 04:28 PM)zinzeur Wrote: This is a brand new vuln (released about 3 days ago) affecting wordpress websites (any version) with post smtp plugin installed version <=2.8.7 (latest is 2.8.9). It allows complete admin takeover by ressetting password and retrieving sent email from smtp log api . Enjoy !!
ps: The video is mine
video :
Enjoy

Thankkkk yoouuu SO Much

Thankkkk youuuu !!!
Reply
#72
good shit yo ima try this out
Reply
#73
thanks for info, I'm going to try it
Reply
#74
tanks for sharing bro
Reply
#75
thank you so much
Reply
#76
thanks for sharing going to watch it.
Reply
#77
Does this exploit still work?
Reply
#78
Interesting find can't wait to see it
Reply
#79
(Jan 14, 2024, 04:28 PM)zinzeur Wrote: This is a brand new vuln (released about 3 days ago) affecting wordpress websites (any version) with post smtp plugin installed version <=2.8.7 (latest is 2.8.9). It allows complete admin takeover by ressetting password and retrieving sent email from smtp log api . Enjoy !!
ps: The video is mine
video :
Enjoy

lets see this one
~~ Quick edit

So i tried this , unfortunately this begs to be authorized in most of modern wordpress sites in order to acces this /wp-json or the full /wp-json/post-smtp/v1/connect-app in which the whole vulnerability is revolving on
Reply
#80
(Jan 14, 2024, 04:28 PM)zinzeur Wrote: This is a brand new vuln (released about 3 days ago) affecting wordpress websites (any version) with post smtp plugin installed version <=2.8.7 (latest is 2.8.9). It allows complete admin takeover by ressetting password and retrieving sent email from smtp log api . Enjoy !!
ps: The video is mine
video :
Enjoy
it is surprising that there is such a vulnerability in a software such as WordPress.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  POC CVE-2025-24071 caca28sapo1 16 1,076 4 hours ago
Last Post: ucy
  Google Dorks for finding SQL injection vulnerabilities and other security issues 1yush 68 3,456 4 hours ago
Last Post: 89UI
  New Zer0 Day Wordpress A3g00n 82 3,788 Yesterday, 01:14 PM
Last Post: wker
  {SECRET} DATABASE OF EXPLOITS lulagain 440 27,794 May 07, 2026, 09:44 PM
Last Post: caribou
  Dokan Pro Unauthenticated SQL Injection POC | CVSS 10 Loki 44 4,109 May 07, 2026, 04:45 PM
Last Post: Insulina

Forum Jump:


 Users browsing this forum: 1 Guest(s)