Crawlomatic Multipage Scraper Post Generator WordPress 插件在 2.6.8.1 及之前的所有版本中,由于 crawlomatic_generate_featured_image() 函数缺少文件类型验证,导致存在任意文件上传漏洞。这使得未经身份验证的攻击者能够在受影响站点服务器上上传任意文件,从而可能实现远程代码执行。
usage: python3 CVE-2025-4389.py
git clone https://github.com/Yucaerin/CVE-2025-4389.git
cd CVE-2025-4389
本脚本仅供教育目的使用。请负责任地使用,并仅在你明确获得授权的系统上运行。未经授权使用此脚本是非法且不道德的。