目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2025-8359 PoC — WordPress plugin AdForest 安全漏洞

来源
关联漏洞
标题: WordPress plugin AdForest 安全漏洞 (CVE-2025-8359)
Description:WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是一个应用插件。 WordPress plugin AdForest 6.0.9及之前版本存在安全漏洞,该漏洞源于身份验证不当,可能导致认证绕过。
Description
AdForest <= 6.0.9 - Authentication Bypass to Admin
介绍
# CVE-2025-8359
AdForest &lt;= 6.0.9 - Authentication Bypass to Admin
# 🚨 AdForest <= 6.0.9 - Authentication Bypass to Admin

## 📦 Repository

> **Repo:** [Nxploited/CVE-2025-8359](https://github.com/Nxploited/CVE-2025-8359)  
> **Exploit Script:** `CVE-2025-8359.py`

---

## 📋 Description

> **CVE:** CVE-2025-8359  
> **Vulnerability Type:** Authentication Bypass  
> **Affected Product:** [AdForest - Classified Ads WordPress Theme](https://themeforest.net/item/adforest-classified-ads-wordpress-theme/19481695)  
> **Affected Versions:** Up to and including 6.0.9  
> **CVSS Score:** **9.8 (Critical)**

The AdForest theme for WordPress is vulnerable to an **Authentication Bypass** flaw in all versions up to 6.0.9.  
Due to improper validation of user identity during authentication, an unauthenticated attacker can log in as **any user**, including administrators—without needing a password. This allows full compromise of WordPress sites using AdForest.

---

## 🛠️ Script Overview

This repository contains a professional Python exploit script: `CVE-2025-8359.py`  
The script automates exploitation, intelligently testing all possible phone number formats to maximize success.  
It can authenticate as any user (including admin) and recover valid WordPress login cookies for hijacking sessions.

**Key Features:**
- Multi-variant phone format testing (`+`, spaces, encoding, etc).
- Auto-detection of user ID from server response.
- Robust session and error handling.
- Clear output with admin cookie extraction.

---

## 🚀 Usage

1. **Clone the repository:**
   ```bash
   git clone https://github.com/Nxploited/CVE-2025-8359.git
   cd CVE-2025-8359
   ```

2. **Install dependencies:**
   ```bash
   pip install requests
   ```

3. **Run the exploit script:**
   ```bash
   python CVE-2025-8359.py -u "http://target.com/wordpress" -p "+966 555 555 555" -i 1
   ```
   - `-u` : Base URL of WordPress installation.
   - `-p` : Target user's phone number (as stored in DB).
   - `-i` : Target user ID (e.g., `1` for admin).
   - `-n` : Name value (optional, default "test").

4. **Show script help:**
   ```bash
   python CVE-2025-8359.py -h
   ```

---

## 📦 Requirements

- Python 3.7+
- [`requests`](https://pypi.org/project/requests/)  
  Install via: `pip install requests`

---

## 🧾 Valid Output

- **If exploitation is successful:**
  ```
  [+] Logged in! Cookie: wordpress_logged_in_xxxxxx=xxxxxxx
  ```
  You have a valid WordPress authentication cookie for the target user.

- **If all formats fail:**
  ```
  [-] All variants failed. Try other phone formats or check the database.
  ```

---

## 🍪 Cookie Usage

Once exploitation is successful, the script prints the recovered authentication cookie.

**How to use the cookie:**
- Copy the `wordpress_logged_in_...` value.
- Inject the cookie into your browser session (using a browser extension, or DevTools).
- Visit `/wp-admin/` on the target site. If the exploit succeeded, you will have admin access.

**Example (with Chrome extension):**
1. Install "EditThisCookie" or similar.
2. Add the cookie for your target site:
   - Name: `wordpress_logged_in_xxxxxx`
   - Value: `xxxxxxx` (as printed by the script)
3. Refresh the page for admin access.

---

## ⚠️ Disclaimer

This project and exploit are for **educational and authorized penetration testing purposes only**.  
The author is **not responsible** for any misuse or damage caused by this exploit.  
Always obtain proper permission before testing any systems.

---

## ✨ By: _**Nxploited ( Khaled Alenazi )**_
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →