Post #3917214
2026-07-18 17:23 UTC
If you're looking at the #Wordpress PoC for https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q at https://github.com/attackercan/wp2shell-poc2 , please be aware that the "check" and "read" PoC do not always work. I assume it was created on an empty Wordpress install (with 0 posts). But if it's populated, the OR SLEEP(3) is short circuited away. Trust your version.php instead.
(wp2shell-poc does not have an issue tracker enabled to report this to.)
#sqlinjection #vulnerability #cve #infosec
Replies (0)
No replies.