Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2014-4725 PoC — WordPress MailPoet Newsletters插件远程文件上传漏洞

Source
Associated Vulnerability
Title:WordPress MailPoet Newsletters插件远程文件上传漏洞 (CVE-2014-4725)
Description:The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.
Description
exploiter
Readme
# CVE-2014-4725 mailpoet exploitation tool

this script is used to scan and exploit the cve-2014-4725 vulnerability (mailpoet/wysija newsletters) in wordpress.

## features
- scan mode > detect wordpress targets vulnerable to cve-2014-4725
- exploit mode > upload a zip payload to vulnerable targets

## installation
1. clone the repository:
   ```
   git clone https://github.com/username/mass-cve-2014-4725.git
   cd MASS-CVE-2014-4725
2. install dependencies:
   ```
    pip install requests
## usage

scan targets

python exploit.py --scan targets.txt

targets.txt contains a list of targets (one per line, without http://)


exploit targets

python exploit.py --exploit vuln.txt --payload file/zip.zip

vuln.txt contains targets that are already confirmed vulnerable

--payload is the zip file containing the theme/backdoor to be uploaded


output

vuln.txt > list of vulnerable targets

shell.txt > urls of uploaded shells

File Snapshot

[4.0K] /data/pocs/a79faf9ea04476ca2fb087f396d73c051b6f2d17 ├── [3.9K] exploit.py ├── [4.0K] file │   └── [ 169] ZIP.zip ├── [4.0K] pwdnx │   ├── [ 10] exploited.php │   └── [1.2K] __init__.pyc └── [ 930] README.md 2 directories, 5 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →