Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-9978 PoC — WordPress social-warfare插件跨站脚本漏洞

Source
Associated Vulnerability
Title:WordPress social-warfare插件跨站脚本漏洞 (CVE-2019-9978)
Description:The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.
Description
Wordpress Social Warfare Remote Code Execution (AUTO UPLOAD SHELL)
Readme
# Social Warfare Plugin Wordpress (3.5.2) Remote Code Execution
Wordpress Social Warfare Remote Code Execution (AUTO UPLOAD SHELL)

> Date: March, 2019

> Download Link: https://wordpress.org/plugins/social-warfare/

> Reference: https://wpvulndb.com/vulnerabilities/9259

> Version: <= 3.5.2

> CVE: 2019-9978

# USAGE:

> **python script.py list-of-sites.txt**
File Snapshot

[4.0K] /data/pocs/cf7c7bca0a11d7e8510b0313e250bbd5650e0d80 ├── [ 363] README.md └── [5.6K] wp-rce.py 0 directories, 2 files
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →