$ cat writeup.md…
$ cat writeup.md…
hackerlab
Task: WordPress 6.5.2 with vulnerable WP Automatic 3.55.4 plugin, full server compromise required. Solution: CVE-2024-27956 SQLi to reset admin password, webshell upload for RCE, plaintext SSH credentials in webroot, doas+find GTFOBins privesc to root.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar