Blog Logo
Sebastian Neef - 0day.work

  • Home
  • Contact
  • @0daywork
  • @gehaxelt
  • Impressum
  • Datenschutz

CVE-2023-6294: popup-builder <= 4.2.6 Admin+ SSRF & File Read

31 January 2024  cve

In this blog post I'll describe the details of CVE-2023-6294, a local file inclusion in WordPress' popup-builder plugin.

CVE-2023-6295: so-widgets-bundle < 1.51.0 - Admin+ Local File Inclusion

12 December 2023  cve

In this blog post I'll describe the details of CVE-2023-6295, a local file inclusion in WordPress' so-widgets-bundle plugin.

InfiniteWP Client < 1.9.4.5 - Authentication Bypass

15 January 2020  writeups, cve

I was browsing wpvulndb.com when I stumbled upon the InfiniteWP Client authentication bypass. Being curios, I wanted to reverse engineer the unpublished PoC. Here's my (short) journey.

Open Redirects In Improperly Configured mod_rewrite Rules (PoC for CVE-2019-10098?)

29 October 2019  cve, writeups, research

I recently came across the following Apache vulnerability [https://httpd.apache.org/security/vulnerabilities_24.html]: "mod_rewrite potential open redirect (CVE-2019-10098)", but I couldn't find

Proof of Concept for "Wordpress <=5.2.3: viewing unauthenticated posts" (CVE-2019-17671)

20 October 2019  writeups, cve

A couple of days Wordpress released 5.2.4 with a few security patches. Props to J.D. Grimes who found and disclosed a method of viewing unauthenticated posts. caught

Page 1 of 2 Older Posts →
© 2025 Sebastian Neef - 0day.work All rights reserved.

Coder Ghost Theme created by Milos Bejda
Proudly published with Ghost