CVE-2024-10728: ultimate-post
## The Exploit An authenticated WordPress user with Subscriber role or above can install and activate arbitrary plugins without administrative permission. ```http POST /wp-admin/admin-ajax.php HTTP/1.1 Host: target.wordpress.local Content...
Read article →