Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-51793 — Exploits CVE-2024-51793 unauthenticated arbitrary file upload in WordPress Computer Repair Shop plugin, scans target lists, uploads PHP webshells, and reports vulnerable sites. | Kitploit
Tools/GitHubGitHub/0axz-tools/cve-2024-51793
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed TeamingPayload Development
GitHub0axz-tools/cve-2024-51793

CVE-2024-51793

Exploits CVE-2024-51793 unauthenticated arbitrary file upload in WordPress Computer Repair Shop plugin, scans target lists, uploads PHP webshells, and reports vulnerable sites.

View Repository
4910 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-51793 Exploit Tool Documentation 📋 Overview CVE-2024-51793 is an unauthenticated arbitrary file upload vulnerability in the Computer Repair Shop WordPress plugin (versions prior to 3.8116). This vulnerability allows attackers to upload arbitrary files, including PHP webshells, without authentication, leading to remote code execution on vulnerable WordPress sites.

🚨 Vulnerability Details CVE ID: CVE-2024-51793

Vulnerability Type: Unauthenticated Arbitrary File Upload

Affected Plugin: Computer Repair Shop WordPress Plugin

Affected Versions: < 3.8116

Risk Level: Critical (CVSS Score: 9.8)

🔧 Technical Details The vulnerability exists in the wc_upload_file_ajax action handler in the plugin, which fails to properly validate file types and user authentication, allowing unauthenticated attackers to upload malicious files directly to the server.

📦 Installation & Requirements Prerequisites Python 3.6+

Required packages: requests

Installation bash

Clone or download the script

git clone cd cve-2024-51793-exploit

Install required packages

pip install requests

Or if you have requirements.txt

pip install -r requirements.txt 🛠️ Usage Guide Basic Usage bash python3 cve_2024_51793_exploit.py -l targets.txt -t 50 Advanced Usage bash

With custom output directory

python3 cve_2024_51793_exploit.py -l targets.txt -t 100 -o results

With verbose output (if implemented)

python3 cve_2024_51793_exploit.py -l urls.txt -t 50 --verbose Command Line Arguments Argument Short Description Default --list -l Path to file containing target URLs (required) - --threads -t Number of concurrent threads 50 --output -o Output directory for results results Input File Format Create a text file (targets.txt) with one URL per line:

text example.com https://vulnerable-site.com http://192.168.1.100/wordpress test-site.org/blog 🔍 How It Works

  1. Target Validation The script first checks if the target is running the vulnerable plugin version by examining:

text /wp-content/plugins/computer-repair-shop/readme.txt 2. Version Detection It verifies the plugin contains "CRM WordPress Plugin" and the version is below 3.8116.

  1. Exploitation If vulnerable, the script uploads a PHP webshell via:

text POST /wp-admin/admin-ajax.php?action=wc_upload_file_ajax 4. Webshell Payload The uploaded webshell provides:

File upload capability

Basic file management

Persistent backdoor access

📊 Output Files The tool generates two main output files:

vulnerable_targets.txt - List of confirmed vulnerable URLs

webshells.txt - List of successfully uploaded webshell URLs

🎯 Example Execution bash $ python3 cve_2024_51793_exploit.py -l targets.txt -t 30

root@kitploit:~
╔══════════════════════════════════════════════════════════════╗
║                                                              ║
║  CVE-2024-51793 Exploit Tool                                ║
║  Unauthenticated RCE in Computer Repair Shop WP Plugin      ║
║                                                              ║
╚══════════════════════════════════════════════════════════════╝

[ INFO ] Loaded 150 unique targets [ INFO ] Starting scan with 30 threads

[ SCANNING ] Checking: http://example.com/ [ VULNERABLE ] Target identified: http://example.com/ [ SUCCESS ] Shell uploaded: http://example.com/wp-content/uploads/2024/05/3287428974_ktn.php

[ SCANNING ] Checking: http://testsite.com/ [ NOT VULNERABLE ] Target: http://testsite.com/

[ COMPLETED ] Scan finished successfully 🛡️ Defensive Measures For Website Owners Immediate Actions:

Update Computer Repair Shop plugin to version 3.8116 or later

Remove any uploaded malicious files

Scan for existing compromises

Preventive Measures:

Implement web application firewalls (WAF)

Regular security audits

File integrity monitoring

For Security Researchers Use only in authorized environments

Follow responsible disclosure practices

Obtain proper permissions before testing

⚠️ Legal & Ethical Considerations This tool is for educational and authorized security testing only

Unauthorized use against systems you don't own is illegal

Always obtain proper authorization before penetration testing

Follow responsible disclosure practices for found vulnerabilities

🔄 Maintenance Updates Regularly check for:

Script updates and improvements

Changes in vulnerability status

New detection methods

Troubleshooting Common issues and solutions:

Connection Timeouts: Increase timeout values in session configuration

False Negatives: Verify target URLs are accessible

Rate Limiting: Reduce thread count and add delays

📞 Support For issues and improvements:

Create issues on the project repository

Contact: TG: @KtN_1990

📚 References CVE-2024-51793 Official Entry

WordPress Plugin Directory

[Security Advisory References]

Disclaimer: This tool should only be used for legitimate security research and authorized penetration testing. The authors are not responsible for any misuse or damage caused by this tool.

Download Tool