Files
CVEs-PoC/2014/CVE-2014-4725.md
T
2025-09-29 21:09:30 +02:00

939 B

CVE-2014-4725

Description

The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.

POC

Reference

No PoCs from references.

Github