Sploitus

Exploit for Unrestricted Upload of File with Dangerous Type in Royal-Elementor-Addons Royal Elementor Addons

githubexploit Β· 2023-11-02

Exploit Code

README27 lines
## https://sploitus.com/exploit?id=9B08C779-6AD6-5D43-9099-7CCB8B1E68D7
# πŸš€ WordPress Royal Elementor Addons and Templates Exploit

Exploit for the unauthenticated file upload vulnerability in Royal Elementor Addons and Templates  -v
    ```
   Or use the following command to exploit a list of URLs:
    ```bash
    python3.10 exploit.py -l  -v
    ```

Optional arguments:  
`-f, --file` : Use a custom PHP file to upload  
`-o, --output`: Save vulnerable URLs to an output file  
`-t, --threads`: Specify the number of threads to use (default is 200)  
`-T, --timeout`: Specify the request timeout in seconds (default is 10)

## πŸ“£ Disclaimer

🚫 **Usage of this exploit without prior mutual consent is illegal.** It's the end user's responsibility to obey all applicable local, state, and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program.

## ⚠️ Advisory

Ensure your WordPress installations are fully updated to safeguard against this vulnerability. Particularly, update the `Royal Elementor Addons and Templates` plugin to version 1.3.79 or later.

## πŸ™ Acknowledgements

Kudos to all researchers and developers working hard to protect the web!