Skip to content
KitploitKITPLOIT
OutilsExploitsBlog
Log in
Soumettre
OutilsExploitsBlog
Soumettre

Outils de Hacking, PenTest et Cybersécurité pour votre Arsenal de Sécurité !

Kitploit est un répertoire d'outils de hacking, de cybersécurité et de pentesting. Découvrez les dernières mises à jour des projets pour trouver des vulnérabilités, analyser des systèmes, automatiser les tests et renforcer votre sécurité.

FluxContactConfidentialité© 2026 Kitploit

Répertoire d'outils

Catégories

Voir toutes les catégories
Loading categories
CVE-2026-27540 — Suite d'exploitation Python pour CVE-2026-27540, une RCE par téléversement de fichier non authentifié dans le plugin WooCommerce Wholesale Lead Capture, avec fingerprinting, ciblage par lots et une charge utile de panneau RCE. | Kitploit
Outils/GitHubGitHub/winrarzipsexploit/cve-2026-27540
Scanners de VulnérabilitésGénération de PayloadsExploitationExploitation d'Applications WebSécurité WebTests d'IntrusionRed TeamingOutil d'Accès à Distance
GitHub
winrarzipsexploit/cve-2026-27540

CVE-2026-27540

Suite d'exploitation Python pour CVE-2026-27540, une RCE par téléversement de fichier non authentifié dans le plugin WooCommerce Wholesale Lead Capture, avec fingerprinting, ciblage par lots et une charge utile de panneau RCE.

Voir le dépôt
il y a 14 joursPas encore vérifié

Populaires

Voir tout →

Découvrez les outils les plus utilisés par notre communauté.

Explorer tous les outils

Parcourez notre collection d'outils

Voir tous les outils →
Partager



🌐 Language / Dil

Türkçe English

📌 Özet

WooCommerce Wholesale Lead Capture (WWLC) — Kimlik doğrulamasız dosya yükleme → RCE

ÜrünWooCommerce Wholesale Lead Capture — wwlc eklentisi
Sürüm≤ 2.0.3.1
Fixed2.0.3.2+ — upload handler korumalı
AuthUnauthenticated
Vektöradmin-ajax.php?action=wwlc_file_upload_handler
Fieldfile (multipart upload)
Yazılan yerWordPress uploads dizini
Payloadpayloads/x7-panel.php

🛡️ Fix

  1. WWLC 2.0.3.2+ güncelle
  2. Uploads dizininde PHP execution kapat
  3. WAF: wwlc_file_upload_handler POST rate-limit

📦 Kurulum

git clone https://github.com/winrarzipsexploit/CVE-2026-27540.git
cd CVE-2026-27540
pip install -r requirements.txt
DosyaGörev
winrarzips_brand.pyCMD banner (by winrarzips)
wwlc_core.pyExploit motoru
CVE-2026-27540-Suite.pyBatch + tek hedef CLI
payloads/x7-panel.phpRCE panel
requirements.txtBağımlılıklar

❌ Hedef listesi, tarama sonucu ve panel URL'leri repo'da yok.

🎯 Tek hedef

python CVE-2026-27540-Suite.py -u https://LAB-URL --fingerprint
python CVE-2026-27540-Suite.py -u https://LAB-URL --yes

📦 Toplu (kendi listende)

python CVE-2026-27540-Suite.py -f targets.txt --yes --threads 12

🏷️ Hata etiketleri

patched_version_* · plugin_not_found · wwlc_absent_or_blocked · upload_ok_verify_failed


📌 Résumé

WooCommerce Wholesale Lead Capture (WWLC) — Téléversement de fichier non authentifié → RCE

ProduitWooCommerce Wholesale Lead Capture — plugin wwlc
Affecté≤ 2.0.3.1
Corrigé2.0.3.2+ — gestionnaire de téléversement renforcé
AuthNon authentifié
Vecteuradmin-ajax.php?action=wwlc_file_upload_handler
Champfile (téléversement multipart)
Chemin d'écritureRépertoire uploads de WordPress
Payloadpayloads/x7-panel.php

🛡️ Remédiation

  1. Mettre à jour WWLC vers 2.0.3.2+
  2. Désactiver l'exécution PHP dans le répertoire uploads
  3. WAF : limiter le débit des requêtes POST vers wwlc_file_upload_handler

📦 Installation

git clone https://github.com/winrarzipsexploit/CVE-2026-27540.git
cd CVE-2026-27540
pip install -r requirements.txt
FichierRôle
winrarzips_brand.pyBannière CMD (by winrarzips)
wwlc_core.pyCœur de l'exploit
CVE-2026-27540-Suite.pyCLI batch + cible unique
payloads/x7-panel.phpPayload du panneau RCE
requirements.txtDépendances

❌ Les listes de cibles, les résultats de scan et les URL de panneaux actifs ne sont pas inclus.

🎯 Cible unique

python CVE-2026-27540-Suite.py -u https://LAB-URL --fingerprint
python CVE-2026-27540-Suite.py -u https://LAB-URL --yes

📦 Batch (votre propre liste)

python CVE-2026-27540-Suite.py -f targets.txt --yes --threads 12

🏷️ Tags d'erreur

patched_version_* · plugin_not_found · wwlc_absent_or_blocked · upload_ok_verify_failed


⚠️ Authorized testing / lab use only · Yalnızca yetkili test


Telegram



Télécharger l’outil