CVE-2026-27540 के लिए Python exploit suite, जो WooCommerce Wholesale Lead Capture plugin में unauthenticated file upload RCE है, जिसमें fingerprinting, batch targeting, और एक RCE panel payload शामिल है।
WooCommerce Wholesale Lead Capture (WWLC) — बिना प्रमाणीकरण फ़ाइल अपलोड → RCE
| उत्पाद | WooCommerce Wholesale Lead Capture — wwlc प्लगइन |
| संस्करण | ≤ 2.0.3.1 |
| Fixed | 2.0.3.2+ — upload handler सुरक्षित |
| Auth | Unauthenticated |
| वेक्टर | admin-ajax.php?action=wwlc_file_upload_handler |
| फ़ील्ड | file (multipart upload) |
| लिखने का स्थान | WordPress uploads निर्देशिका |
| Payload | payloads/x7-panel.php |
wwlc_file_upload_handler POST rate-limitgit clone https://github.com/winrarzipsexploit/CVE-2026-27540.git
cd CVE-2026-27540
pip install -r requirements.txt
| फ़ाइल | कार्य |
|---|---|
winrarzips_brand.py | CMD बैनर (by winrarzips) |
wwlc_core.py | Exploit इंजन |
CVE-2026-27540-Suite.py | Batch + एकल लक्ष्य CLI |
payloads/x7-panel.php | RCE पैनल |
requirements.txt | निर्भरताएँ |
❌ लक्ष्य सूची, स्कैन परिणाम और पैनल URL repo में नहीं हैं।
python CVE-2026-27540-Suite.py -u https://LAB-URL --fingerprint
python CVE-2026-27540-Suite.py -u https://LAB-URL --yes
python CVE-2026-27540-Suite.py -f targets.txt --yes --threads 12
patched_version_* · plugin_not_found · wwlc_absent_or_blocked · upload_ok_verify_failed
WooCommerce Wholesale Lead Capture (WWLC) — बिना प्रमाणीकरण फ़ाइल अपलोड → RCE
| उत्पाद | WooCommerce Wholesale Lead Capture — wwlc प्लगइन |
| प्रभावित | ≤ 2.0.3.1 |
| Fixed | 2.0.3.2+ — upload handler सुरक्षित |
| Auth | Unauthenticated |
| वेक्टर | admin-ajax.php?action=wwlc_file_upload_handler |
| फ़ील्ड | file (multipart upload) |
| लिखने का स्थान | WordPress uploads निर्देशिका |
| Payload | payloads/x7-panel.php |
wwlc_file_upload_handler POST अनुरोधों को rate-limit करेंgit clone https://github.com/winrarzipsexploit/CVE-2026-27540.git
cd CVE-2026-27540
pip install -r requirements.txt
| फ़ाइल | भूमिका |
|---|---|
winrarzips_brand.py | CMD बैनर (by winrarzips) |
wwlc_core.py | Exploit कोर |
CVE-2026-27540-Suite.py | Batch + एकल-लक्ष्य CLI |
payloads/x7-panel.php | RCE पैनल payload |
requirements.txt | निर्भरताएँ |
❌ लक्ष्य सूचियाँ, स्कैन परिणाम और लाइव पैनल URL शामिल नहीं हैं।
python CVE-2026-27540-Suite.py -u https://LAB-URL --fingerprint
python CVE-2026-27540-Suite.py -u https://LAB-URL --yes
python CVE-2026-27540-Suite.py -f targets.txt --yes --threads 12
patched_version_* · plugin_not_found · wwlc_absent_or_blocked · upload_ok_verify_failed