# Cadre d'exploitation pour CVE-2026-82222, une RCE non authentifiée dans le plugin WordPress GiveWP. Prend en charge l'analyse de masse, la détection automatique, le multi-threading, la sortie JSON/TXT et un shell interactif pour les tests autorisés.
CVE-2026-82222 - GiveWP Unauthenticated RCE Exploit
Mass Scanner + Auto-Detection + Multi-Threading + Interactive Shell
GHOSTLYR00T est un framework d'exploitation pour CVE-2026-82222, une vulnérabilité d'injection d'objets PHP dans le plugin GiveWP de WordPress permettant une exécution de code à distance (RCE) sans authentification. Cet outil prend en charge le scan de masse, l'auto-détection et un shell interactif.
🔴 CVSS 9.8 - CRITIQUE
Vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
| Fitur | Deskripsi |
|---|---|
| Mass Scan | Scan ratusan target dari file (-f targets.txt) |
| Auto-Detection | Deteksi otomatis form ID, gateway, dan amount donasi |
| Multi-Threading | Scan paralel dengan thread configurable (--threads) |
| Check Mode | Fingerprint cepat tanpa exploit (--check) |
| JSON Output | Export hasil ke JSON (--json) |
| TXT Output | Export hasil ke TXT ringkas (--txt) |
| Interactive Shell | Upload webshell + terminal interaktif |
| Admin Escalation | Auto-escalate user ke administrator |
| Progress Bar | Monitor real-time proses scanning |
| Colored Output | Output dengan warna dan format profesional |
| Feature | Description |
|---|---|
| Mass Scan | Scan hundreds of targets from file (-f targets.txt) |
| Auto-Detection | Auto-detects form ID, gateway, and donation amount |
| Multi-Threading | Parallel scanning with configurable threads |
| Check Mode | Fast fingerprint without exploitation (--check) |
| JSON Output | Export results to JSON (--json) |
| TXT Output | Export results to TXT (--txt) |
| Interactive Shell | Upload webshell + interactive terminal |
| Admin Escalation | Auto-escalate user to administrator |
| Progress Bar | Real-time scan progress monitoring |
| Colored Output | Professional colored terminal output |