目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2025-3515 PoC — WordPress plugin Drag and Drop Multiple File Upload for Contact Form 代码问题漏洞

来源
关联漏洞
标题: WordPress plugin Drag and Drop Multiple File Upload for Contact Form 代码问题漏洞 (CVE-2025-3515)
Description:WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。WordPress plugin是一个应用插件。 WordPress plugin Drag and Drop Multiple File Upload for Contact Form 7 1.3.8.9及之前版本存在代码问题漏洞,该漏洞源于文件类型验证不足,可能导致未经验证攻击者上传.phar等危险文件类
Description
CVE-2025-3515 WordPress lab for Drag and Drop Multiple File Upload for CF7: Dockerized PoC & Nuclei testing
介绍
# CVE-2025-3515 WordPress Lab (Drag and Drop Multiple File Upload for Contact Form 7)

Spin up a vulnerable WordPress environment to reproduce and validate CVE-2025-3515 — unrestricted file upload via `ddmu_upload_file` in the plugin `drag-and-drop-multiple-file-upload-contact-form-7` (≤ 1.3.8.9). This lab is Dockerized for quick, deterministic testing with Nuclei.

- Vulnerable plugin: `drag-and-drop-multiple-file-upload-contact-form-7` v1.3.8.9
- Core dependency: Contact Form 7 (auto-installed)
- Endpoint of interest: `/wp-admin/admin-ajax.php?action=ddmu_upload_file`

## Quickstart

1. Start the lab

```bash
docker compose up -d
```

1. Wait 15-45s for init. Confirm WP is reachable:

```bash
curl -I http://localhost:8080/wp-login.php | head -n1
```

1. Run the Nuclei PoC template from repo root

```bash
nuclei -u http://localhost:8080 -t http/cves/2025/CVE-2025-3515.yaml -vv -debug
```

Containerized alternative (uses the same docker network):

```bash
docker run --rm --network lab-cve-2025-3515_default \
  -v "$(pwd)":/workspace \
  projectdiscovery/nuclei:latest \
  -u http://wordpress \
  -t /workspace/http/cves/2025/CVE-2025-3515.yaml -vv -debug
```

### Credentials

- WP Admin: admin / admin

### Notes

- This lab demonstrates arbitrary file upload and code execution under Apache + mod_php style containers. The included Nuclei template uploads a short PHP payload that self-deletes after echoing a marker for verification.
- For safety, only run against local or authorized targets.

### Tags / Topics

wordpress, contact-form-7, drag-and-drop-multiple-file-upload-contact-form-7, ddmu_upload_file, arbitrary file upload, rce, nuclei, docker lab, security research, CVE-2025-3515
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →