This repository was archived by the owner on Oct 22, 2020. It is now read-only.
v1.5.3
Bug Fixes
- Fix some modules statically referencing the wp-content directory
- Fix authenticated modules causing the follow_http_redirection option to be set to false
- Fix a null reference when using Hydra via HttpClient#queue_request
New Modules
- Add 53 new modules for BestWebSoft plugin reflected XSS shell upload
- Add Answer My Question 1.3 reflected XSS shell upload
- Add Download Monitor <= 1.9.6 log export
- Add MSMC reflected XSS shell upload
- Add Slideshow Gallery <= 1.6.5 reflected XSS shell upload
- Add Tracking Code Manager reflected XSS shell upload
- Add Ultimate Addons for Visual Composer <= 3.16.11 authenticated stored XSS shell upload
- Add Ultimate Addons for Visual Composer <= 3.16.11 reflected XSS shell upload
- Add Ultimate Form Builder Lite <= 1.3.2 reflected XSS shell upload
- Add User Access Manager reflected XSS shell upload
- Add WordPress Ad Widget <= 2.11.0 - authenticated PHP file download
- Add WordPress Firewall 2 authenticated stored XSS shell upload
- Add flickr-picture-backup <= 0.7 unauthenticated shell upload