
Proof-of-Concept-Exploit für CVE-2024-7627, eine nicht authentifizierte Remote-Code-Ausführungs-Sicherheitslücke im Bit File Manager WordPress-Plugin. Automatisiert Nonce-Extraktion, Ausnutzung von Race-Conditions und bietet eine interaktive Reverse Shell.
Dieses Repository enthält einen Proof-of-Concept (PoC)-Exploit für CVE-2024-7627, eine kritische Unauthenticated Remote Code Execution (RCE)-Sicherheitslücke im Bit File Manager WordPress-Plugin (Versionen 6.0 – 6.5.5).
Wenn die Funktion Gastbenutzer-Lesen aktiviert ist, legt das Plugin eine Race Condition in der checkSyntax-Funktion offen.
Diese Funktion schreibt vor der Validierung eine temporäre PHP-Datei in /wp-content/uploads/, sodass Angreifer die Datei anfordern und beliebige Systembefehle ausführen können.
requests, aiohttp, asyncio, beautifulsoup4Abhängigkeiten installieren:
pip install requests aiohttp beautifulsoup4
[*] Getting a valid AJAX nonce...
[+] Found the valid AJAX nonce: 65a1d91c63
[*] Getting a random file hash...
[+] Starting interactive shell. Type 'exit' to quit.
lab-shell> id
uid=33(www-data) gid=33(www-data) groups=33(www-data)
lab-shell> uname -a
Linux victim-wp 5.15.0-78-generic #85-Ubuntu SMP x86_64 GNU/Linux
lab-shell> whoami
www-data