
PoC for CVE-2026-6433: WordPress FlipperCode Custom CSS, JS & PHP (≤2.0.7) — unauthenticated SQLi to RCE. Python 3 stdlib; single target or bulk multi-threaded scanning. Authorized testing & research only.
FlipperCode — Custom CSS, JS & PHP · Unauthenticated SQL injection → RCE (via eval())
Affected: FlipperCode Custom CSS, JS & PHP ≤ 2.0.7 · WordPress plugin surface via admin-ajax.php
| Item | Detail |
|---|---|
| Vector | Unauthenticated SQLi tunneled through plugin AJAX actions |
| Impact | Remote code execution on the WordPress host (payload written to docroot, then executed in PHP context) |
| Script | CVE-2026-6433.py — stdlib only (urllib, ssl, threading, concurrent.futures) |
| Modes | Single URL or bulk file with multi-threaded workers |
| Discovery | Dr. John Umoru, ClarenSec Limited |
| Bulk / threading | github.com/murrez |
flowchart TB
subgraph prep[" Preconditions "]
A["Target runs vulnerable plugin"]
B["admin-ajax reachable"]
end
subgraph chain[" Exploit chain "]
C["POST fc_ajax_call / wce_editor_inline_code"]
D["SQLi injects PHP payload"]
E["Proof file written under DOCUMENT_ROOT"]
F["Optional: fetch proof / run command output"]
G["Default: remote unlink cleanup"]
end
A --> C
B --> C
C --> D --> E --> F --> G
On GitHub, badges, tables, and diagrams render with strong visual contrast. This document is structured so you can skim (badges + tables) or read deeply (sections below).
pip install required — standard library only)Clone or download this folder, then:
# Help / all flags
python CVE-2026-6433.py --help
# PHP-only proof (writes a small proof file; good for locked-down shells)
python CVE-2026-6433.py https://target.example --php-only --no-cleanup
# Run an OS command and print captured output (if execution functions exist remotely)
python CVE-2026-6433.py https://target.example --command "id"
# Only attempt to delete the proof file (cleanup mode)
python CVE-2026-6433.py https://target.example --cleanup-only
Use a text file with one base URL per line. Lines starting with # and blank lines are ignored.
python CVE-2026-6433.py --bulk targets.txt --threads 8
Example targets.txt:
# Lab hosts — replace with authorized systems only
https://site-a.example
https://site-b.example
Notes:
--bulk at the same time.min(threads, len(targets))).1 if any bulk target fails.| Flag | Meaning |
|---|---|
target | Single WordPress base URL (omit when using --bulk) |
--command CMD | Run shell command remotely (uses shell_exec, exec, system, passthru, or popen when available) |
--php-only | Write PHP metadata proof instead of relying on --command |
--no-cleanup | Do not delete the remote proof file after a successful run |
--proof-name NAME | Remote filename (default: rce-proof.txt) |
--cleanup-only | Only send unlink payload and report whether the file is gone |
--bulk FILE | Read many targets from FILE |
--threads N | Concurrent workers for --bulk (default: 5) |
FAIL: … and the process exits with code 1.[Bulk scan] summarize progress.[OK] or [FAIL] with a reason.--no-cleanup when you must preserve evidence in an authorized engagement.| Role | Credit |
|---|---|
| Original discovery | Dr. John Umoru — ClarenSec Limited |
| Bulk / multi-threaded harness | github.com/murrez |
[!WARNING] Legal & ethical use only
This proof-of-concept exists for education, defensive research, and authorized security testing.
Running it against systems without explicit written permission may violate computer misuse laws in your jurisdiction.
The authors and contributors accept no liability for misuse.
Last README structure tuned for readability: badges · tables · flowchart · explicit flags.