WordPress RCE Exploitation & Mitigation (CVE-2020-25213)
📌 Project Overview
This project was developed as part of the IE4012 – Offensive Hacking Tactics & Strategies module.
It demonstrates a full cybersecurity attack lifecycle in a controlled lab environment, including:
- Social engineering attack
- Malware simulation
- Vulnerability exploitation
- VAPT analysis
- Security patch implementation
🎯 Target Vulnerability
- CVE ID: CVE-2020-25213
- Vulnerability: WordPress File Manager Plugin Remote Code Execution
- Severity: Critical (CVSS 9.8)
- Type: Unauthenticated File Upload → RCE
🧪 Lab Environment
| Role | OS | IP |
|---|
| Attacker | Kali Linux | x.x.x.x |
| Victim | Ubuntu + WordPress | y.y.y.y |
⚔️ Attack Chain
- Phishing Email (Fake WordPress Update)
- Malware Execution (Trojanized Installer)
- Conditional Trigger (Network Detection)
- Exploitation of CVE-2020-25213
- Web Shell Upload
- Remote Code Execution
- Nmap
- WPScan
- Burp Suite
- Netcat
- Metasploit
- Gobuster
🔍 Key Features
- Social engineering-based infection
- Automated vulnerability exploitation
- Malware behavior simulation
- Post-exploitation access
- Full VAPT methodology
- Patch development and testing
🛡️ Mitigation & Patch
- Updated plugin (v6.9+)
- Added authentication checks
- Blocked PHP file uploads
- Implemented WAF rules
- Secured file handling
📊 Impact
- Confidentiality: HIGH
- Integrity: HIGH
- Availability: HIGH
📁 Project Structure
/report
/malware
/exploit
/patch
/screenshots
👨💻 Author
- Name: Jayarathna K.P.G.C.M
📎 References
- CVE-2020-25213 Documentation
- WordPress Security Advisories