Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-50498 PoC — WordPress plugin WP Query Console 代码注入漏洞

Source
Associated Vulnerability
Title:WordPress plugin WP Query Console 代码注入漏洞 (CVE-2024-50498)
Description:WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是一个应用插件。 WordPress plugin WP Query Console 1.0版本及之前版本存在代码注入漏洞,该漏洞源于代码生成控制不当,导致代码注入漏洞。
Description
This is a exploit for CVE-2024-50498
Readme
# CVE-2024-50498
# Affected Version
  `WP Query Console <=1.0`
# Credit
  `https://github.com/RandomRobbieBF/CVE-2024-50498`
# Premise
## Query Type is WP_Query and WP Query Console executes some php functions 
![Vulnerabilities](./pictures/1.png)
# Usage
`python .\CVE-2024-50498.py 192.168.41.163 --query "id"`
![result](./pictures/2.png)
File Snapshot

[4.0K] /data/pocs/158ce36a17dc55f701718307ed970f10145b1f89 ├── [2.5K] CVE-2024-50498.py ├── [4.0K] pictures │   ├── [ 95K] 1.png │   ├── [ 33K] 2.png │   └── [ 1] README.md ├── [ 341] README.md └── [1.3M] wp-query-console.zip 1 directory, 6 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.