Automated RCE exploit for WordPress WPCode Lite v2.3.5 (CVE-2026-8832) with 8 built-in PHP payloads, XML-RPC bypass, and web-based interactive shell for authorized penetration testing.
An exploitation tool to test for Remote Code Execution (RCE) vulnerabilities in the WordPress plugin WPCode Lite (Insert Headers and Footers) v2.3.5. This vulnerability stems from registering the Custom Post Type (CPT) wpcode without defining a custom capability_type. This oversight allows any user with the Author role (or higher) to execute arbitrary PHP code on the server via XML-RPC.
Credit: Created based on the vulnerability analysis by t.me/Fanatix_Legion.
FOR AUTHORIZED SECURITY TESTING ONLY. Unauthorized usage of this tool against systems you do not own is ILLEGAL. Use this strictly on systems where you have explicit, written permission to conduct penetration testing. The author assumes no liability and is not responsible for any misuse or damage caused by this program.
wp.newPost endpoint via XML-RPC to bypass plugin UI administrative protections.disable_functions restrictions commonly found in shared hosting environments (like CloudLinux) which block functions like shell_exec and system.requests librarypip install requests
Run the script from your terminal/command prompt:
python wpcode_rce_tester.py
The tool will prompt you interactively for the following:
http://localhost).get_current_user) and OS info (php_uname).?cmd= parameter).phpinfo().DOCUMENT_ROOT natively using scandir().To secure your WordPress site:
add_filter('xmlrpc_enabled', '__return_false');