WordPress MailPoet Newsletters (wysija-newsletters) Unauthenticated File Upload

The WordPress plugin “MailPoet Newsletters” (wysija-newsletters) before 2.6.8 is vulnerable to an unauthenticated file upload. The exploit uses the Upload Theme functionality to upload a zip file containing the payload. The plugin uses the admin_init hook, which is also executed for unauthenticated users when accessing a specific URL. The first fix for this vulnerability appeared in version 2.6.7, but the fix can be bypassed. In PHP’s default configuration, a POST variable overwrites a GET variable in the $_REQUEST array. The plugin uses $_REQUEST to check for access rights. By setting the POST parameter to something not beginning with ‘wysija_’, the check is bypassed. WordPress uses the $_GET array to determine the page, so it is not affected by this. The developers applied the fixes to all previous versions too.


Module Name



  • Marc-Alexandre Montpas
  • Christian Mehlmauer <FireFart [at] gmail.com>



  • wysija-newsletters < 2.6.8


  • php


  • php



Module Options

To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:




Introduce tus datos o haz clic en un icono para iniciar sesión:

Logo de WordPress.com

Estás comentando usando tu cuenta de WordPress.com. Cerrar sesión / Cambiar )

Imagen de Twitter

Estás comentando usando tu cuenta de Twitter. Cerrar sesión / Cambiar )

Foto de Facebook

Estás comentando usando tu cuenta de Facebook. Cerrar sesión / Cambiar )

Google+ photo

Estás comentando usando tu cuenta de Google+. Cerrar sesión / Cambiar )

Conectando a %s