Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-27540 — Python exploit suite for CVE-2026-27540, an unauthenticated file upload RCE in the WooCommerce Wholesale Lead Capture plugin, with fingerprinting, batch targeting, and an RCE panel payload. | Kitploit
Tools/GitHubGitHub/winrarzipsexploit/cve-2026-27540
Vulnerability ScannersPayload GenerationExploitationWeb Application ExploitationWeb SecurityPenetration TestingRed TeamingRemote Access Tool
GitHub
winrarzipsexploit/cve-2026-27540

CVE-2026-27540

Python exploit suite for CVE-2026-27540, an unauthenticated file upload RCE in the WooCommerce Wholesale Lead Capture plugin, with fingerprinting, batch targeting, and an RCE panel payload.

View Repository
115 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share



🌐 Language / Dil

Türkçe English

📌 Özet

WooCommerce Wholesale Lead Capture (WWLC) — Kimlik doğrulamasız dosya yükleme → RCE

ÜrünWooCommerce Wholesale Lead Capture — wwlc eklentisi
Sürüm≤ 2.0.3.1
Fixed2.0.3.2+ — upload handler korumalı
AuthUnauthenticated
Vektöradmin-ajax.php?action=wwlc_file_upload_handler
Fieldfile (multipart upload)
Yazılan yerWordPress uploads dizini
Payloadpayloads/x7-panel.php

🛡️ Fix

  1. WWLC 2.0.3.2+ güncelle
  2. Uploads dizininde PHP execution kapat
  3. WAF: wwlc_file_upload_handler POST rate-limit

📦 Kurulum

git clone https://github.com/winrarzipsexploit/CVE-2026-27540.git
cd CVE-2026-27540
pip install -r requirements.txt
DosyaGörev
winrarzips_brand.pyCMD banner (by winrarzips)
wwlc_core.pyExploit motoru
CVE-2026-27540-Suite.pyBatch + tek hedef CLI
payloads/x7-panel.phpRCE panel
requirements.txtBağımlılıklar

❌ Hedef listesi, tarama sonucu ve panel URL'leri repo'da yok.

🎯 Tek hedef

python CVE-2026-27540-Suite.py -u https://LAB-URL --fingerprint
python CVE-2026-27540-Suite.py -u https://LAB-URL --yes

📦 Toplu (kendi listende)

python CVE-2026-27540-Suite.py -f targets.txt --yes --threads 12

🏷️ Hata etiketleri

patched_version_* · plugin_not_found · wwlc_absent_or_blocked · upload_ok_verify_failed


📌 Summary

WooCommerce Wholesale Lead Capture (WWLC) — Unauthenticated file upload → RCE

ProductWooCommerce Wholesale Lead Capture — wwlc plugin
Affected≤ 2.0.3.1
Fixed2.0.3.2+ — upload handler hardened
AuthUnauthenticated
Vectoradmin-ajax.php?action=wwlc_file_upload_handler
Fieldfile (multipart upload)
Write pathWordPress uploads directory
Payloadpayloads/x7-panel.php

🛡️ Remediation

  1. Upgrade WWLC to 2.0.3.2+
  2. Disable PHP execution in uploads directory
  3. WAF: rate-limit wwlc_file_upload_handler POST requests

📦 Setup

git clone https://github.com/winrarzipsexploit/CVE-2026-27540.git
cd CVE-2026-27540
pip install -r requirements.txt
FileRole
winrarzips_brand.pyCMD banner (by winrarzips)
wwlc_core.pyExploit core
CVE-2026-27540-Suite.pyBatch + single-target CLI
payloads/x7-panel.phpRCE panel payload
requirements.txtDependencies

❌ Target lists, scan results and live panel URLs are not included.

🎯 Single target

python CVE-2026-27540-Suite.py -u https://LAB-URL --fingerprint
python CVE-2026-27540-Suite.py -u https://LAB-URL --yes

📦 Batch (your own list)

python CVE-2026-27540-Suite.py -f targets.txt --yes --threads 12

🏷️ Error tags

patched_version_* · plugin_not_found · wwlc_absent_or_blocked · upload_ok_verify_failed


⚠️ Authorized testing / lab use only · Yalnızca yetkili test


Telegram



Download Tool