
Day 21/100 vulnerable WordPress lab (VulnpreX) to sharpen recon skills beyond HTB. Fingerprinted WordPress 5.8 and identified two live vulnerable plugins: Social Warfare 3.5.2 (unauth RCE, CVE-2019-9978) and Mail Masta 1.0 (LFI). @commando_skiipz @ce3nerd @DefendWithFelix https://t.co/Ds8cr3iMe4
Post summary
A live WordPress lab discovered that the Social Warfare plugin version 3.5.2 has an unauthenticated RCE (CVE-2019-9978); no exploit code, patch, or active exploitation details were provided.

