xsspresso
xsspresso
Tags/ WordPress

WordPress

5 writeups tagged with WordPress

WebMediumLinux

VHL — Dolphin

Dolphin CMS with a WordPress instance on port 81. Admin credential brute-force leads to plugin RCE and privilege escalation.

#Dolphin CMS#WordPress#Brute Force
Feb 12, 2025Virtual Hacking Labs
WebEasyLinux

VHL — Techblog

WordPress 4.7.2 on CentOS. Exploited outdated plugin for remote code execution and escalated via sudo misconfiguration.

#WordPress#RCE#Sudo
Feb 8, 2025Virtual Hacking Labs
WebMediumLinux

HTB — BigBang

WordPress BuddyForms plugin SSRF for local file read. Grafana SQLite injection for credentials. Telescope log viewer arbitrary file read for root key.

#WordPress#SSRF#Grafana
Jan 26, 2025HackTheBox
WebMediumLinux

HTB — Tartarsauce

Gwolle Guestbook WordPress RFI via robots.txt discovery. Lateral move through sudo tar with --checkpoint shell execution.

#WordPress#RFI#Sudo
Apr 13, 2022HackTheBox
CryptoInsaneLinux

HTB — Brainfuck

Insane box chaining WordPress plugin creds, SMTP sniffing, RSA private key crack, and Vigenère cipher decode.

#WordPress#RSA#Vigenère
Mar 7, 2022HackTheBox