How hackers exploit XSS vulnerabilities to create admin accounts on your WordPress blog

preview_player
Показать описание
Рекомендации по теме
Комментарии
Автор

Wtf? You just copied two random html script import tag and then you logged in wordpress admin panel, typing the password. Where is the hacking here?

swarmer_
Автор

This assumes you have the Onetone theme or similar with import feature for custom code/css

neuemage
Автор

What is pass after all ( Administrator)?

mujkicsamir
Автор

The majn probleem is we cant see any username or password in terminal😂

MustafaNightcore
Автор

Show us how you got the script...like start from scratch

daironism
Автор

How did he opened the terminal into the site and import ?

SsoFee
Автор

what is action "onetone_options_import" in admin-ajax.php in WP ? I don't see it in source code in standard actions....

apristen
Автор

Oh my god... 😂 what is this video lmao

nacho
Автор

I tray but widout sucess WordPress Version: 5.9.2

relaxingandsatisfying
Автор

will it work if wordpress user(Victim) set an option not allow to register a new user?

cyberwarrior_
Автор

Doesn't explain anything, and no idea where you managed to get the password from...

jackepner