Skip to content

Instantly share code, notes, and snippets.

View seven0525's full-sized avatar

ahpjop seven0525

View GitHub Profile
@seven0525
seven0525 / inject.py
Created March 20, 2019 05:33 — forked from leonjza/inject.py
Wordpress 4.7.0/4.7.1 Unauthenticated Content Injection PoC
# 2017 - @leonjza
#
# Wordpress 4.7.0/4.7.1 Unauthenticated Content Injection PoC
# Full bug description: https://blog.sucuri.net/2017/02/content-injection-vulnerability-wordpress-rest-api.html
# Usage example:
#
# List available posts:
#
# $ python inject.py http://localhost:8070/