
Unauthenticated 0-click RCE exploit for CVE-2024-50498. Exploits a code injection vulnerability in the LUBUS WP Query Console plugin to execute arbitrary PHP code, write a web shell to the uploads directory, detect the target operating system, and achieve remote command execution via an interactive shell.

This repository contains a proof-of-concept exploit for CVE-2024-50498, an unauthenticated code injection vulnerability in the LUBUS WP Query Console WordPress plugin, leading to remote command execution (RCE).
The script sends a crafted POST request to a vulnerable REST endpoint to inject and execute arbitrary PHP code. It writes a web shell into the WordPress uploads directory, detects the target operating system, and provides an interactive remote shell.
python CVE-2024-50498.py --target http://target-wordpress-site
After execution, the script deploys the payload, verifies its accessibility, detects the OS, and drops into an interactive shell.