PoC Index

CVE-2014-4725

HIGH 7.5EPSS 59.7%

The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
59.68% chance of exploitation in the next 30 days, 99th percentile
Published
2014-07-27
Updated
2024-08-06

Proof-of-concept exploits (5)

Metasploit modules (1)

ExploitDB entries (1)

References

Related