Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2019-11223 — CVE-2019-11223 - Arbitrary File Upload in Wordpress Support Candy Plugin Version 2.0 Below | Kitploit
Tools/GitHubGitHub/angelctulhu/cve-2019-11223
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubangelctulhu/cve-2019-11223

CVE-2019-11223

CVE-2019-11223 - Arbitrary File Upload in Wordpress Support Candy Plugin Version 2.0 Below

View Repository
3617 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2019-11223

Arbitrary File Upload in Wordpress Plugin SupportCandy Version 2.0 Below

  • https://cert.kalasag.com.ph/news/research/vulnerable-wordpress-plugin-lets-you-take-over-websites/
  • https://wordpress.org/plugins/supportcandy/#developers
  • https://www.pluginvulnerabilities.com/2019/04/05/arbitrary-file-upload-vulnerability-in-supportcandy/

Getting Started

root@kitploit:~
git clone https://github.com/AngelCtulhu/CVE-2019-11223.git

Prerequisites

root@kitploit:~
pip install requests

Exploitation

in exploit.py change localhost to your target

root@kitploit:~
python exploit.py
"http:\/\/localhost\/wp-content\/uploads\/wpsc\/1555513124_shell.php"

Authors

  • Christian Angel - KALASAG CERT

License

This project is licensed under the MIT License - see the LICENSE file for details

Download Tool