## https://sploitus.com/exploit?id=9E58530F-43FD-5EF6-896D-CE6DD1E1DC98
# CVE-2023-3460
Exploit for CVE-2023-3460 - Unauthorized admin access for Ultimate Member plugin. Made with Golang
```
ββββββββββββββββββββββββββββββββββββββββββββββββββββ ββββββββββββββββββββββββββββββββββββββββββββββββββββ
β DISCLAIMER β β ABOUT THE PROJECT β
β β β β
β This Proof of Concept (PoC) has been developed β β I had problems in some cases with this exploit. β
β for educational and research purposes only. β β Things like this must happen since it's a dev β
β Its intention is to explore potential security β β version. Project intended to increase the scope β
β vulnerabilities and raise awareness about them. β β of the exploit, and not need to open BurpSuite β
β β β and test by hand everytime you find a Wordpress β
β USAGE DISCLAIMER: β β WebApp. Improvements are on the way, and I β
β Any use of this PoC on systems or websites you β β promise I won't leave the dirty code as it is β
β do not have explicit authorization for may β β (I think). β
β violate ethical standards and legal regulations. β β β
β β β UPCOMING FEATURES: β
β USAGE AT YOUR OWN RISK: β β - Scanning functionality to identify exposed β
β Using this PoC on unauthorized systems or β β systems β
β websites may lead to legal consequences. Always β β - Improved nonce search for various registration β
β obtain proper authorization before testing. β β patterns β
β β β - Customizable admin creation options (Like set β
β The creator of this PoC are not responsible β β parameters that registration require) β
β for any misuse or damage caused by its usage. β β β
β β β β
β [ Version 0.1 ] β β [ By BlackReaperSK ] β
ββββββββββββββββββββββββββββββββββββββββββββββββββββ ββββββββββββββββββββββββββββββββββββββββββββββββββββ
```