Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
wordpress-rce-vapt-cve-2020-25213 — Educational cybersecurity project demonstrating exploitation and mitigation of CVE-2020-25213 (WordPress File Manager Plugin RCE). Includes malware simulation, VAPT analysis, and security patch implementation in a controlled lab environment. | Kitploit
Tools/GitHubGitHub/cmadhushanka/wordpress-rce-vapt-cve-2020-25213
Vulnerability AnalysisExploitationWeb Application ExploitationPhishingMalware AnalysisPenetration TestingSocial EngineeringLearning & EducationLabs & Practice
GitHubcmadhushanka/wordpress-rce-vapt-cve-2020-25213

wordpress-rce-vapt-cve-2020-25213

Educational cybersecurity project demonstrating exploitation and mitigation of CVE-2020-25213 (WordPress File Manager Plugin RCE). Includes malware simulation, VAPT analysis, and security patch implementation in a controlled lab environment.

View Repository
174 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

WordPress RCE Exploitation & Mitigation (CVE-2020-25213)

📌 Project Overview

This project was developed as part of the IE4012 – Offensive Hacking Tactics & Strategies module.

It demonstrates a full cybersecurity attack lifecycle in a controlled lab environment, including:

  • Social engineering attack
  • Malware simulation
  • Vulnerability exploitation
  • VAPT analysis
  • Security patch implementation

🎯 Target Vulnerability

  • CVE ID: CVE-2020-25213
  • Vulnerability: WordPress File Manager Plugin Remote Code Execution
  • Severity: Critical (CVSS 9.8)
  • Type: Unauthenticated File Upload → RCE

🧪 Lab Environment

RoleOSIP
AttackerKali Linuxx.x.x.x
VictimUbuntu + WordPressy.y.y.y

⚔️ Attack Chain

  1. Phishing Email (Fake WordPress Update)
  2. Malware Execution (Trojanized Installer)
  3. Conditional Trigger (Network Detection)
  4. Exploitation of CVE-2020-25213
  5. Web Shell Upload
  6. Remote Code Execution

🛠 Tools Used

  • Nmap
  • WPScan
  • Burp Suite
  • Netcat
  • Metasploit
  • Gobuster

🔍 Key Features

  • Social engineering-based infection
  • Automated vulnerability exploitation
  • Malware behavior simulation
  • Post-exploitation access
  • Full VAPT methodology
  • Patch development and testing

🛡️ Mitigation & Patch

  • Updated plugin (v6.9+)
  • Added authentication checks
  • Blocked PHP file uploads
  • Implemented WAF rules
  • Secured file handling

📊 Impact

  • Confidentiality: HIGH
  • Integrity: HIGH
  • Availability: HIGH

📁 Project Structure

/report
/malware
/exploit
/patch
/screenshots

👨‍💻 Author

  • Name: Jayarathna K.P.G.C.M

📎 References

  • CVE-2020-25213 Documentation
  • WordPress Security Advisories

Download Tool