Exploitation Summary
EIP tracks 1 public exploit for CVE-2015-10139.
PoCs published by Evex, rastating, including Metasploit module auxiliary/admin/http/wp_wplms_privilege_escalation.
AI-analyzed exploit summary This Metasploit module exploits a privilege escalation vulnerability in the WordPress WPLMS theme by manipulating system options via the import_data function. It changes the admin email, enables user registration, and sets the default role to administrator, allowing an attacker to create a new admin account.
Description
The WPLMS theme for WordPress is vulnerable to Privilege Escalation in versions 1.5.2 to 1.8.4.1 via the 'wp_ajax_import_data' AJAX action. This makes it possible for authenticated attackers to change otherwise restricted settings and potentially create a new accessible admin account.
Exploits (1)
This Metasploit module exploits a privilege escalation vulnerability in the WordPress WPLMS theme by manipulating system options via the import_data function. It changes the admin email, enables user registration, and sets the default role to administrator, allowing an attacker to create a new admin account.
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H