Sploitus

Exploit for Authentication Bypass by Spoofing in Booster Booster For Woocommerce

githubexploit Β· 2026-02-16

Exploit Code

README229 lines
## https://sploitus.com/exploit?id=2E84A936-8E96-544C-806E-DCEEEA9B7810
# QE3 - WordPress Auto Exploitation Scanner



```
╔═══════════════════════════════════════════════════════════════╗
β•‘    β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—     β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—      β•‘
β•‘   β–ˆβ–ˆβ•”β•β•β•β–ˆβ–ˆβ•—β–ˆβ–ˆβ•”β•β•β•β•β•β•šβ•β•β•β•β–ˆβ–ˆβ•—    β–ˆβ–ˆβ•”β•β•β•β•β•β–ˆβ–ˆβ•”β•β•β•β•β•β–ˆβ–ˆβ•”β•β•β•β•β•      β•‘
β•‘   β–ˆβ–ˆβ•‘   β–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—   β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•    β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—  β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—      β•‘
β•‘   β–ˆβ–ˆβ•‘β–„β–„ β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β•β•β•   β•šβ•β•β•β–ˆβ–ˆβ•—    β–ˆβ–ˆβ•”β•β•β•  β•šβ•β•β•β•β–ˆβ–ˆβ•‘β•šβ•β•β•β•β–ˆβ–ˆβ•‘      β•‘
β•‘   β•šβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•    β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•‘β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•‘      β•‘
β•‘    β•šβ•β•β–€β–€β•β• β•šβ•β•β•β•β•β•β•β•šβ•β•β•β•β•β•     β•šβ•β•β•β•β•β•β•β•šβ•β•β•β•β•β•β•β•šβ•β•β•β•β•β•β•      β•‘
β•šβ•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•
```

**Ultimate WordPress Vulnerability Scanner & Exploiter**

[![Python](https://img.shields.io/badge/Python-3.7+-blue.svg)](https://www.python.org/)
[![License](https://img.shields.io/badge/License-MIT-green.svg)](LICENSE)
[![Exploits](https://img.shields.io/badge/Exploits-7-red.svg)](README.md)
[![Version](https://img.shields.io/badge/Version-7.0_Final-orange.svg)](README.md)

[Features](#-features) β€’ [Installation](#-installation) β€’ [Usage](#-usage) β€’ [Exploits](#-exploits) β€’ [FOFA Integration](#-fofa-integration)



---

## πŸ“– About

**QE3** adalah automated WordPress exploitation scanner yang dirancang untuk security testing. Tool ini dapat mendeteksi dan mengeksploitasi berbagai vulnerability di WordPress plugins, themes, dan core dengan satu command.

### ✨ Kenapa QE3?

- πŸš€ **Fully Automated** - Scan, detect, exploit, verify dalam satu command
- 🎯 **7 Built-in Exploits** - Support CVE terbaru 2025-2026
- πŸ’‰ **Smart Shell Injection** - Triple execution methods untuk maximum compatibility
- πŸ” **FOFA Integration** - Mass scanning dari FOFA search results
- βœ… **Zero False Positives** - Hanya report shell yang verified dengan `uid=` output
- πŸ“Š **Beautiful Output** - Clean interface dengan colors dan symbols
- πŸ’Ύ **Auto Save** - Working shells otomatis tersimpan ke `berhasil.txt`

---

## 🎯 Features

### Core Features

| Feature | Description |
|---------|-------------|
| **Auto Plugin Detection** | Deteksi installed plugins dan versions |
| **Version Checking** | Compare dengan vulnerable versions |
| **Multiple Exploits** | 7 different exploitation methods |
| **Smart Shell Testing** | Triple execution: system(), shell_exec(), eval() |
| **UID Verification** | Only report shells with verified `uid=` output |
| **Single & Mass Scan** | Support single target atau list.txt |
| **FOFA Dorks** | Built-in dorks untuk mass target hunting |
| **Auto Save** | Working shells saved to berhasil.txt |

### Output Features

βœ“ **Plugin Version Display** - Shows if Vulnerable/Patched/Unknown  
βœ“ **Beautiful Symbols** - βœ“ βœ— β†’ ⚠ 🎯 untuk easy reading  
βœ“ **Failure Reasons** - Detailed explanation kenapa exploit gagal  
βœ“ **UID Output** - Display actual `uid=33(www-data)` output  
βœ“ **Progress Tracking** - Real-time progress untuk mass scanning  
βœ“ **Summary Report** - Complete statistics di akhir scan  

---

## πŸ”₯ Exploits

QE3 v7.0 Final supports **7 automated exploits**:

| # | Exploit | CVE | Type | Auth | Year |
|---|---------|-----|------|------|------|
| 1 | WordPress LFI | wp_lang | Path Traversal + Log Poisoning | ❌ | 2024 |
| 2 | Melis CMS Slider | - | Unrestricted Upload | ❌ | 2025 |
| 3 | g-FFL Checkout | CVE-2025-68001 | Unrestricted Upload | ❌ | 2025 |
| 4 | WPvivid Backup | CVE-2026-1357 | RCE via AES Encryption | ❌ | 2026 |
| 5 | Hash Form | CVE-2024-5084 | File Upload | ❌ | 2024 |
| 6 | KiotViet | CVE-2025-12674 | REST API Upload | ❌ | 2025 |
| 7 | Generic Upload | - | Multiple Methods | ❌ | - |

### πŸ”₯ Latest CVEs (2025-2026)

- **CVE-2025-68001** - g-FFL Checkout Plugin (Jan 2026)
- **CVE-2025-12674** - KiotViet Integration (Dec 2025)
- **CVE-2026-1357** - WPvivid Backup Unauth RCE (Jan 2026)

---

## πŸ“¦ Installation

### Requirements

- Python 3.7+
- pip

### Quick Install

```bash
# Clone repository
git clone https://github.com/Sincan2/wordpress-Exploit-2026.git
cd wordpress-Exploit-2026

# Install dependencies
pip install -r requirements.txt

# Make executable
chmod +x qe3.py

# Run
./qe3.py --help
```

### Dependencies

```
requests>=2.31.0
colorama>=0.4.6
pycryptodome>=3.19.0
```

---

## πŸš€ Usage

### Basic Usage

```bash
# Single target
./qe3.py example.com

# With protocol
./qe3.py https://example.com

# Multiple targets
./qe3.py list.txt

# Show FOFA dorks
./qe3.py --dorks
```

### Single Target Example

```bash
$ ./qe3.py example.com

╔═══════════════════════════════════════════════════════════════╗
β•‘        WordPress Auto Scanner v7.0 FINAL                     β•‘
β•šβ•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•

[Single Target Mode]

──────────────────────────────────────────────────────────────────
🎯 Target: https://example.com
──────────────────────────────────────────────────────────────────

βœ“ Connected via HTTPS

[Scanning Plugins]
  βœ“ VULNERABLE wpvivid-backuprestore
    └─ Version: 0.9.85 | Vuln:  targets.txt

# 4. Scan with QE3
./qe3.py targets.txt

# 5. View results
cat berhasil.txt
```

---

## πŸ“Š Output Files

### berhasil.txt

Format: `Timestamp | Domain | Shell URL | Method`

```
2026-02-15 14:30:12 | example.com | https://example.com/wp-content/uploads/qn.php | WPvivid
2026-02-15 14:31:45 | test.com | https://test.com/wp-content/uploads/g-ffl/shell.php | g-FFL
```

---

## πŸ“ˆ Success Rates

Based on real-world testing:

| Exploit | Success Rate | Notes |
|---------|--------------|-------|
| g-FFL Checkout | **~95%** | If plugin detected |
| Melis CMS | **~85%** | Common in corporate sites |
| WordPress LFI | **~40%** | Core vulnerability |
| WPvivid Unauth | **~30%** | Popular backup plugin |
| **Overall** | **~35-40%** | From FOFA results |

---

## πŸ›‘οΈ Legal Disclaimer

**IMPORTANT - READ CAREFULLY:**

This tool is for **educational and authorized security testing only**.

βœ… **Legal Use:**
- Testing your own websites
- Authorized penetration testing with written permission
- Security research in controlled environments

❌ **Illegal Use:**
- Unauthorized access to systems you don't own
- Testing without explicit permission
- Any malicious activities

**BY USING THIS TOOL YOU AGREE:**
- You have authorization to test target systems
- Authors are not responsible for misuse

---



**Made with ❀️ by MHL Team**

*For educational purposes only. Use responsibly.*