wordpress XMLRPC.php RCE ?
by itsBlackNight - Saturday March 30, 2024 at 01:59 AM
#1
Greetings gentlemen !

I need some help concerning this : In a wordpress website I can POST request to xmlrpc.php & and I'm stuck a little bit .

Tried to bruteforce some password with the method wpuserblog with a username that i got through wpscan but bruteforcing is too fking slow for me took me 4 hours to test 1000 custom password
I've seen that there's a possibility to get some remote code execution if the website is running php [SOURCE] . But that didn't work for me

X-Powered-By: PHP/8.2.16
Server: LiteSpeed

if you have any idea feel free to share ! Thank you
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  new wordpress website takeover vuln (video + poc ) zinzeur 313 27,277 03-28-2026, 02:43 AM
Last Post: toshi99
  CVE-2025-40554 - SolarWinds Web Help Desk Auth Bypass & RCE PoC miyako 3 73 02-07-2026, 03:32 PM
Last Post: cysc
  HPE OneView RCE Exploit [CVE-2025-37164] Hawx01 8 261 02-06-2026, 07:08 PM
Last Post: hacker0123
  WordPress LFI to RCE - CVE-2025-0366 Serious 1 457 02-05-2026, 09:53 AM
Last Post: Sammm89
  New Zer0 Day Wordpress A3g00n 77 2,626 02-05-2026, 01:46 AM
Last Post: StrangeVest



 Users browsing this thread: