
WordPress RomethemeKit For Elementor 插件 <= 1.5.4 存在远程代码执行(RCE)漏洞
该脚本利用 RomethemeKit For Elementor WordPress 插件(<= v1.5.4) 中的一个严重漏洞,该漏洞允许经过身份验证的任意插件安装与激活,最终可能导致远程代码执行(RCE)。
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H该漏洞允许经过身份验证的攻击者(拥有管理员权限)以编程方式安装并激活任意插件——包括可能带有恶意的插件——从而可能导致在服务器上执行任意代码。
python3 CVE-2025-30911.py -u http://target/wordpress -un admin -p password -pl hello-dolly/hello.php
usage:
CVE-2025-30911.py [-h] -u URL -un USERNAME -p PASSWORD [-pl PLUGIN]
Exploit For CVE-2025-30911 | By Nxploited Khaled Alenazi
options:
-h, --help Show this help message and exit
-u, --url URL Base URL of the WordPress site
-un, --username USERNAME WordPress admin username
-p, --password PASSWORD WordPress admin password
-pl, --plugin PLUGIN Plugin to install (default: hello-dolly/hello.php)
python3 CVE-2025-30911.py -u http://192.168.100.74:888/wordpress -un admin -p admin -pl hello-dolly/hello.php
requests 库(通过 pip install requests 安装)本工具仅用于教育和授权安全测试。未经授权的使用是违法且不道德的。
作者:Nxploited | Khaled Alenazi