WordPress Plugin Contact Form Builder [CSRF → LFI]

2019-04-21 Thread Panagiotis Vagenas
# Exploit Title: Contact Form Builder [CSRF → LFI] # Date: 2019-03-17 # Exploit Author: Panagiotis Vagenas # Vendor Homepage: http://web-dorado.com/ # Software Link: https://wordpress.org/plugins/contact-form-builder # Version: 1.0.67 # Tested on: WordPress 5.1.1 Description --- Plugin

WordPress plugin Contact Form by WD [CSRF → LFI]

2019-04-05 Thread Panagiotis Vagenas
# Exploit Title: Contact Form by WD [CSRF → LFI] # Date: 2019-03-17 # Exploit Author: Panagiotis Vagenas # Vendor Homepage: http://web-dorado.com/ # Software Link: https://wordpress.org/plugins/contact-form-maker # Version: 1.13.1 # Tested on: WordPress 5.1.1 Description --- Plugin

WordPress Plugin Form Maker by WD [CSRF → LFI]

2019-04-05 Thread Panagiotis Vagenas
# Title: Form Maker by WD [CSRF → LFI] # Date: 2019-03-17 # Exploit Author: Panagiotis Vagenas # Vendor Homepage: http://web-dorado.com/ # Software Link: https://wordpress.org/plugins/form-maker # Version: 1.13.2 # Tested on: WordPress 5.1 Description --- Plugin implements the following

Social Media Widget by Acurax [CSRF]

2018-01-08 Thread Panagiotis Vagenas
* Exploit Title: Social Media Widget by Acurax [CSRF] * Discovery Date: 2017-12-12 * Exploit Author: Panagiotis Vagenas * Author Link: https://twitter.com/panVagenas * Vendor Homepage: http://www.acurax.com/ * Software Link: https://wordpress.org/plugins/acurax-social-media-widget * Version: 3.2.5

Admin Menu Tree Page View [CSRF, Privilege Escalation]

2018-01-08 Thread Panagiotis Vagenas
* Exploit Title: Admin Menu Tree Page View [CSRF, Privilege Escalation] * Discovery Date: 2017-12-12 * Exploit Author: Panagiotis Vagenas * Author Link: https://twitter.com/panVagenas * Vendor Homepage: http://eskapism.se/ * Software Link: https://wordpress.org/plugins/admin-menu-tree-page-view

CMS Tree Page View [CSRF, Privilege Escalation]

2018-01-08 Thread Panagiotis Vagenas
* Exploit Title: CMS Tree Page View [CSRF, Privilege Escalation] * Discovery Date: 2017-12-12 * Exploit Author: Panagiotis Vagenas * Author Link: https://twitter.com/panVagenas * Vendor Homepage: http://eskapism.se/ * Software Link: https://wordpress.org/plugins/cms-tree-page-view * Version: 1.4

WordPress Bulk Delete Plugin [Privilege Escalation]

2016-03-03 Thread Panagiotis Vagenas
* Exploit Title: Bulk Delete [Privilege Escalation] * Discovery Date: 2016-02-10 * Exploit Author: Panagiotis Vagenas * Author Link: https://twitter.com/panVagenas * Vendor Homepage: http://bulkwp.com/ * Software Link: https://wordpress.org/plugins/bulk-delete/ * Version: 5.5.3 * Tested

Extra User Details [Privilege Escalation]

2016-02-24 Thread Panagiotis Vagenas
""" * Exploit Title: Extra User Details [Privilege Escalation] * Discovery Date: 2016-02-13 * Exploit Author: Panagiotis Vagenas * Author Link: https://twitter.com/panVagenas * Vendor Homepage: http://vadimk.com/ * Software Link: https://wordpress.org/plugins/extra-user-details/ *

WordPress WooCommerce - Store Toolkit Plugin [Privilege Escalation]

2016-02-08 Thread Panagiotis Vagenas
* Exploit Title: WordPress WooCommerce - Store Toolkit Plugin [Privilege Escalation] * Discovery Date: 2016-02-06 * Public Disclosure Date: 2016-02-08 * Exploit Author: Panagiotis Vagenas * Contact: https://twitter.com/panVagenas * Vendor Homepage: http://www.visser.com.au/ * Software Link: https

WordPress WP User Frontend Plugin [Unrestricted File Upload]

2016-02-08 Thread Panagiotis Vagenas
* Exploit Title: WordPress WP User Frontend Plugin [Unrestricted File Upload] * Discovery Date: 2016-02-04 * Public Disclosure: 2016-02-08 * Exploit Author: Panagiotis Vagenas * Contact: https://twitter.com/panVagenas * Vendor Homepage: https://wedevs.com * Software Link: https://wordpress.org

WordPress User Meta Manager Plugin [Information Disclosure]

2016-02-07 Thread Panagiotis Vagenas
* Exploit Title: WordPress User Meta Manager Plugin [Information Disclosure] * Discovery Date: 2015-12-28 * Public Disclosure Date: 2016-02-01 * Exploit Author: Panagiotis Vagenas * Contact: https://twitter.com/panVagenas * Vendor Homepage: http://jasonlau.biz/home/ * Software Link: https

WordPress Users Ultra Plugin [Blind SQL injection] - Update

2015-12-10 Thread Panagiotis Vagenas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 * Exploit Title: WordPress Users Ultra Plugin [Blind SQL injection] * Discovery Date: 2015/10/19 * Public Disclosure Date: 2015/12/01 * Exploit Author: Panagiotis Vagenas * Contact: https://twitter.com/panVagenas * Vendor Homepage: http