# CVE-2024-49328-exploit
## 🌟 Overview
This script exploits a privilege escalation vulnerability in the WP REST API FNS Plugin for WordPress. The vulnerability affects all versions up to and including `1.0.0`, allowing unauthenticated attackers to gain administrator privileges.
## ⚙️ Usage
```bash
python script.py -u <site_url> -e <email> -p <password>
```
### 🔍 Details of Exploitation
| **Step** | **Description** | **Icon** |
|----------|---------------------------------------------------------------|--------------------|
| Step 1 | Verify the version of the plugin. | 📝 |
| Step 2 | Check if the version is exploitable (`1.0.0`, or lower).| ✅ |
| Step 3 | Exploit the vulnerability and register a new admin user. | 🔒 |
| Step 4 | Print the result with user credentials for verification. | 🎉 |
## ➡️ Example Output
```
Found Stable tag version: 1.0.0
Version 1.0.0 is exploitable.
Exploiting the site... Please wait.
Successfully
Username: Nxploit@admin.sa
Password: nxploit
```
### Install the required packages
```
pip install requests
```
## ⚠️ Disclaimer
🚨 Warning:
This script is for educational purposes only. Unauthorized use of this script against systems without explicit permission is illegal and unethical.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view