module

Wordpress RegistrationMagic task_ids Authenticated SQLi

Disclosed
Jan 23, 2022
Created
Feb 2, 2022

Description

RegistrationMagic, a WordPress plugin,
prior to 5.0.1.5 is affected by an authenticated SQL injection via the
task_ids parameter.

Authors

h00die
Hacker5preme (Ron Jost)

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':


msf > use auxiliary/scanner/http/wp_registrationmagic_sqli
msf auxiliary(wp_registrationmagic_sqli) > show actions
...actions...
msf auxiliary(wp_registrationmagic_sqli) > set ACTION < action-name >
msf auxiliary(wp_registrationmagic_sqli) > show options
...show and set options...
msf auxiliary(wp_registrationmagic_sqli) > run

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.