The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
9 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a fully functional proof-of-concept exploit for CVE-2023-5360, targeting the Royal Elementor Addons and Templates WordPress plugin (versions <= 1.3.78). The exploit is implemented in a single Python script (exploit.py) that uses only the Python standard library. The exploit works by extracting a nonce from the target site's JavaScript, then abusing the /wp-admin/admin-ajax.php endpoint to upload a PHP web shell (with a crafted filename such as 'poc.ph$p') to the server. If successful, the shell is accessible via a predictable URL under /wp-content/uploads/royal-addons/. The exploit provides remote code execution by allowing arbitrary commands to be run via the uploaded shell. The repository also includes a README.md with detailed usage instructions, requirements, and background on the vulnerability. No third-party dependencies are required, and the exploit is suitable for CTFs, research, and educational purposes.
This repository contains a proof-of-concept exploit for CVE-2023-5360, a file upload vulnerability in the Royal Elementor Addons and Templates WordPress plugin (before version 1.3.79). The exploit is implemented in a single Python script (CVE-2023-5360.py) and is accompanied by a detailed README.md. The script automates the exploitation process: it retrieves a required nonce from a target Elementor page, allows the user to select between uploading a simple PHP webshell or a reverse shell, and attempts to upload the payload via the vulnerable AJAX endpoint (/wp-admin/admin-ajax.php). If successful, the script provides the URL to the uploaded shell (typically under /wp-content/uploads/wpr-addons/forms/). The exploit optionally assists with starting a Netcat listener for reverse shells. The repository is well-structured, with clear usage instructions and example output. No hardcoded endpoints are present; all target URLs are user-supplied. The exploit is a functional POC and does not belong to a larger framework.
This repository contains a single Metasploit module (Ruby file) that exploits an unauthenticated file upload vulnerability (CVE-2023-5360) in the Royal Elementor Addons and Templates WordPress plugin (versions < 1.3.79). The exploit works by first retrieving a nonce from the target site, then uploading a PHP payload disguised as a .ph$p file via the vulnerable 'wpr_addons_upload_file' action exposed through the /wp-admin/admin-ajax.php endpoint. If successful, the module triggers the uploaded payload, resulting in remote code execution on the target server. The module is operational and allows for arbitrary PHP payloads, leveraging Metasploit's payload system. The code is well-structured, includes version checks, and is designed for reliable exploitation. No hardcoded IPs or domains are present; the target is specified by the user. The repository is a typical Metasploit exploit module, with all logic contained in a single Ruby file.
This repository targets CVE-2023-5360, a shell upload vulnerability in the WordPress Royal Elementor Addons plugin (version 1.3.70 and below). The repository contains three files: a README.md describing the exploit, 'exploit.py' (the main exploit script), and 'vulnfinder.py' (a vulnerability scanner). The 'exploit.py' file is heavily obfuscated but is designed to upload a web shell to a vulnerable WordPress site, granting remote code execution. The 'vulnfinder.py' script allows users to scan multiple WordPress domains to check if they are running a vulnerable version of the plugin by fetching the plugin's readme.txt file and parsing the version. The attack vector is network-based, requiring access to the target's web interface. The exploit is operational, as it provides a working payload (web shell) but is not part of a larger framework. The repository is focused and practical for attackers seeking to compromise WordPress sites with this specific vulnerable plugin.
This repository contains a working exploit for CVE-2023-5360, an unauthenticated file upload vulnerability in the 'Royal Elementor Addons and Templates' WordPress plugin (versions < 1.3.79). The exploit is implemented in Python (CVE-2023-5360.py and exploit.py), with the main logic in 'exploit.py'. The exploit works by first verifying the presence of the vulnerable plugin on the target, then obtaining a required nonce, and finally uploading a PHP webshell via the vulnerable AJAX endpoint. The PHP payload (webshell) is embedded in the Python code and is designed to allow further file uploads and code execution on the compromised server. The exploit supports both single-target and mass exploitation (via a list of URLs), and can optionally use a custom PHP payload. The repository also includes a README with usage instructions and a requirements.txt for dependencies. The main attack vector is network-based, targeting WordPress sites over HTTP(S) endpoints. The exploit is operational and provides a working webshell if successful.
This repository provides an exploit for CVE-2023-5360, targeting the Royal Elementor Addons and Templates WordPress plugin (versions <= 1.3.78). The exploit is implemented in Python 2.7 and consists of two main scripts: 1. cve-2023-5360.py: This is the main exploit script. It takes a list of target URLs, attempts to exploit the arbitrary file upload vulnerability via the WordPress AJAX endpoint, and uploads a PHP webshell (fetched from a remote GitHub URL) to the target server. If successful, the shell is accessible at a predictable location on the target. 2. scanner.py: This script checks if the target WordPress site is running a vulnerable version of the plugin by fetching and parsing the plugin's readme.txt file. The exploit is unauthenticated and works over the network, requiring only a list of target URLs. The payload is a PHP webshell, enabling remote code execution on compromised servers. The repository is operational and provides a working exploit with a real payload, but is not part of a larger exploitation framework.
This repository contains a Python exploit (exploit.py) targeting CVE-2023-5360, an unauthenticated file upload vulnerability in the Royal Elementor Addons and Templates WordPress plugin (versions <1.3.79). The exploit allows an attacker to upload arbitrary PHP files (such as webshells) to a vulnerable WordPress site without authentication, leading to remote code execution. The script supports scanning single or multiple targets, custom payload uploads, multithreading, and outputting results to a file. It interacts with the target via HTTP(S), specifically checking for the plugin's presence and exploiting the /wp-admin/admin-ajax.php endpoint. The repository also includes a README.md with usage instructions and a requirements.txt for dependencies. The exploit is operational, providing a working attack with customizable payloads.
This repository contains a Python exploit script (CVE-2023-5360.py) targeting CVE-2023-5360, a vulnerability in the Royal Elementor Addons and Templates WordPress plugin (versions before 1.3.79). The vulnerability allows unauthenticated attackers to upload arbitrary files, such as a PHP web shell, to the target WordPress site, resulting in remote code execution (RCE). The main script, CVE-2023-5360.py, is the core of the exploit. It: - Accepts a list of target WordPress site URLs. - Asynchronously checks each site for the presence of the vulnerable plugin and attempts to exploit the file upload flaw. - Uploads a PHP web shell (embedded in the script) to the target if vulnerable. - Logs results to 'exploit.log', and maintains lists of active vulnerable sites and successfully exploited sites in 'active-plugin.txt' and 'exploited.txt' respectively. The repository also includes a README.md with detailed usage instructions, a LICENSE file (MIT), and a requirements.txt.log listing Python dependencies (colorama, requests, urllib3). The exploit is operational, providing a working payload and automation for mass exploitation, but is not part of a larger exploitation framework. No hardcoded IPs or domains are present; the script targets user-supplied URLs. The exploit is intended for educational purposes only, as stated in the documentation.
This repository targets CVE-2023-5360, a shell upload vulnerability in the WordPress Royal Elementor Addons plugin (version 1.3.70 and below). The repository contains three files: a README.md describing the exploit, 'exploit.py' (the main exploit script), and 'vulnfinder.py' (a vulnerability scanner). The 'exploit.py' file is heavily obfuscated but is designed to upload a web shell to a vulnerable WordPress site, granting the attacker remote code execution. The 'vulnfinder.py' script is a multi-threaded scanner that checks a list of WordPress sites for the vulnerable plugin version by fetching '/wp-content/plugins/royal-elementor-addons/readme.txt' and parsing the version. The exploit requires the target to be running the vulnerable plugin and accessible over the network. The overall structure is typical for a WordPress plugin exploit: a scanner to identify targets and an exploit to deliver a web shell.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.