The Canto plugin for WordPress is vulnerable to Remote File Inclusion (RFI) in versions up to and including 3.0.4 via the wp_abspath parameter. If PHP is configured with allow_url_include enabled, an unauthenticated attacker can supply a remote URL to be included, resulting in inclusion and execution of attacker-controlled PHP code on the server. The issue can also be leveraged as a Local File Inclusion (LFI), but practical exploitation for code execution via LFI requires the attacker to have already placed a malicious PHP file on the target host in a web-server-readable location (e.g., via FTP or another upload vector).
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
allow_url_include is enabled, allowing full compromise of the WordPress site and potentially the underlying server context of the web service (e.g., arbitrary command execution as the web server user, data theft/modification, persistence via webshells, and pivoting depending on environment). In configurations where only LFI is feasible, impact is more limited unless the attacker can first place a PHP payload locally; in that case, LFI can be used to execute the planted payload.If you can’t patch tonight, do this now.
allow_url_include in PHP configuration to prevent RFI-style inclusion of remote resources. Additionally, restrict/validate any user-controlled input used in include/require paths (defense-in-depth) and reduce avenues for attackers to place arbitrary PHP files on the host (e.g., harden FTP access, file permissions).Patch, then assume compromise.
wp_abspath parameter (vendor patch).3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a Metasploit exploit module targeting WordPress Canto plugin remote file inclusion leading to unauthenticated RCE (CVE-2023-3452 and CVE-2024-25096). The primary code is a single Ruby Metasploit module (wordpress_canto_plugin_file_include_rce.rb) that: - Fingerprints WordPress via simple content regex. - Checks vulnerability by fetching {TARGETURI}/readme.txt and parsing the 'Stable tag' version, confirming <= 3.0.6, and probing reachability of a selected vulnerable file under {TARGETURI}/includes/lib/{TARGETFILE}. - Exploits by starting an embedded HTTP server (HttpServer::PHPInclude), then sending a GET/POST request to the vulnerable PHP file with either wp_abspath (tree.php/get.php/download.php/detail.php) or abspath (others like sizes.php/copy-media.php) set to the attacker server URL (get_uri). When the target includes the remote URL (requires allow_url_include=On), it executes the served PHP payload and hands off to the Metasploit handler to obtain a session (commonly php/meterpreter/reverse_tcp). Repo structure also includes a docker-compose.yaml and rfi.ini to stand up a local WordPress+MariaDB lab with allow_url_include enabled, plus README instructions for installing specific vulnerable Canto versions and loading the module into Metasploit. No additional exploit code beyond the Metasploit module is present.
Repository contains a single Python exploit script (canto_exploit.py) plus README, LICENSE, and requirements.txt (requests). The exploit targets CVE-2023-3452 in the WordPress Canto plugin (<= 3.0.4), abusing a Remote File Inclusion via the wp_abspath parameter in /wp-content/plugins/canto/includes/lib/download.php to achieve unauthenticated RCE. Operational flow: - Optional vulnerability check: GET /wp-content/plugins/canto/readme.txt, parse 'Stable tag' version and treat <= 3.0.4 as vulnerable (or proceed if version unknown). - Payload staging: writes a malicious PHP file locally at /tmp/canto_exploit/wp-admin/admin.php that executes an attacker-supplied command via PHP system(). - Delivery: starts a local HTTP server bound to 0.0.0.0:<LPORT> serving /tmp/canto_exploit as document root. - Trigger: sends a GET request to the vulnerable download.php with parameter wp_abspath=http://<LHOST>:<LPORT>, causing the target to include the attacker-hosted PHP file and execute it. - Modes: single command execution (default runs 'id; whoami; hostname'), interactive loop for repeated commands, and a reverse-shell helper that executes a bash /dev/tcp reverse shell back to <LHOST>:<shell_port>. Notable implementation details: requests is used with verify=False and urllib3 warnings disabled to work against HTTPS targets without certificate validation. Output is minimally cleaned by truncating at '<br />' to reduce PHP error noise.
This repository provides a working exploit for CVE-2023-3452, a Remote File Inclusion (RFI) and Remote Code Execution (RCE) vulnerability in the Canto WordPress plugin (versions prior to 3.0.5). The main exploit script, 'CVE-2023-3452.py', is a Python tool that automates the attack by setting up a local HTTP server to serve a malicious PHP file (web shell or reverse shell) and then triggering the vulnerable 'download.php' endpoint on the target WordPress site via the 'wp_abspath' parameter. The exploit allows unauthenticated attackers to execute arbitrary PHP code on the target, provided 'allow_url_include' is enabled in PHP. The repository includes a detailed README with usage instructions and background on the vulnerability. The only code file is the exploit script; the other files are documentation and a Google site verification file. The exploit is operational and can be used to gain remote code execution on vulnerable WordPress installations.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.