We reveal a vulnerability in two popular WordPress plugins that, when combined, allow an attacker to remotely execute rogue code on the underlying server. (more…)
Read more »
In the latest episode of JAMstack Radio, Brian speaks with Dan Olson and Shinichi Nishikawa about Shifter, a serverless WordPress hosting solution that pre-renders your site and serves static HTML via CDN. Listen in for details on how Shifter works to del... (more…)
Read more »
Use XSHM to identify WordPress websites running on internal networks and behind firewalls and also launch a login bruteforce attack on them.
Read more »
Simple tool to manage WordPress backups in pure Bash - tanrax/wp-backup... (more…)
Read more »
I was browsing wpvulndb.com when I stumbled upon the InfiniteWP Client authentication bypass. Being curios, I wanted to reverse engineer the unpublished PoC. Here's my (short) journey. Analysis The first step was to browse through the source code which is... (more…)
Read more »