POC - WordPress File Upload plugin, in the wfu_file_downloader.php file before version <= 4.24.11
WordPress File Upload plugin, in the wfu_file_downloader.php file before version <= 4.24.11
Overview
Affected Devices
Affected Components
Getting Started
Finding Targets

Cloning the Repository
Run the Exploit:
For Linux / MacOs:
Example Usage

PreviousCVE-2024-50623- Cleo Unrestricted file upload and downloadNextPOC - Remote and unauthenticated attacker can send crafted HTTP requests to RCE - cve-2025-3248
Last updated