CVE-2014-4725

EXPLOITED

MailPoet Newsletters <2.6.7 - Auth Bypass

Title source: llm
STIX 2.1

Description

The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotephp
https://www.exploit-db.com/exploits/33991
nomisec WORKING POC 1 stars
by AnotherSec · poc
https://github.com/AnotherSec/CVE-2014-4725
vulncheck_xdb WORKING POC
remote
https://github.com/Pwdnx1337/MASS-CVE-2014-4725
metasploit WORKING POC EXCELLENT
by Marc-Alexandre Montpas, Christian Mehlmauer · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/wp_wysija_newsletters_upload.rb

Scores

EPSS 0.8179
EPSS Percentile 99.2%

Details

VulnCheck KEV 2022-12-05
CWE
CWE-287
Status published
Products (50)
mailpoet/mailpoet_newsletters 0.9
mailpoet/mailpoet_newsletters 0.9.1
mailpoet/mailpoet_newsletters 0.9.2
mailpoet/mailpoet_newsletters 0.9.6
mailpoet/mailpoet_newsletters 1.0
mailpoet/mailpoet_newsletters 1.0.1
mailpoet/mailpoet_newsletters 1.1
mailpoet/mailpoet_newsletters 1.1.1
mailpoet/mailpoet_newsletters 1.1.2
mailpoet/mailpoet_newsletters 1.1.3
... and 40 more
Published Jul 27, 2014
Tracked Since Feb 18, 2026