wp-email-subscribers-listing: WordPress Plugin Email Subscribers Listing

日期: 2025-08-01 | 影响软件: WordPress Plugin Email Subscribers Listing | POC: 已公开

漏洞描述

Searches for sensitive directories present in the email-subscribers plugin.

PoC代码[已公开]

id: wp-email-subscribers-listing

info:
  name: WordPress Plugin Email Subscribers Listing
  author: pussycat0x
  severity: low
  description: Searches for sensitive directories present in the email-subscribers plugin.
  reference:
    - https://www.exploit-db.com/ghdb/6428
  metadata:
    max-request: 1
  tags: wordpress,listing,plugin,edb,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/wp-content/plugins/email-subscribers"

    matchers-condition: and
    matchers:
      - type: word
        words:
          - "Index of"
          - "wp-content/plugins/email-subscribers"
        condition: and

      - type: status
        status:
          - 200
# digest: 4a0a0047304502210092fb8ebff28187fe2db9a586998db2857d55bc9bbda798915041a9a636fd1faf02203948efe397c2f412533484883ffb42f091857bcbfb552d1c8752d924daccd7b2:922c64590222798bb761d5b6d8e72950