CVE-2025-6440 is an unrestricted file upload vulnerability in the WooCommerce Designer Pro plugin for WordPress, including when bundled with the Pricom - Printing Company & Design Services theme. The flaw affects all versions up to and including 1.9.26 and is caused by missing server-side file type validation in the AJAX handler function 'wcdp_save_canvas_design_ajax'. Supporting context also indicates the endpoint lacks authentication, authorization, and nonce/CSRF protections. As a result, unauthenticated attackers can submit arbitrary files, including potentially executable PHP payloads, via wp-admin/admin-ajax.php?action=wcdp_save_canvas_design_ajax. Because uploaded files are stored in a web-accessible location such as wp-content/uploads/, an attacker may then directly request the uploaded payload and achieve code execution on the server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
10 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
The repository contains one standalone Python 3 script, `CVE-2025-6440.py`, and no exploit framework modules or bundled shell payload. It is an operational bulk/single-target unauthenticated RCE exploit for the WC Designer Pro WordPress plugin. The script first supports plugin fingerprinting via a plugin CSS asset and an AJAX behavior check, then sends a multipart POST to WordPress `admin-ajax.php` using the `wcdp_save_canvas_design_ajax` action. Its crafted `params` metadata labels the uploaded `file1` as a PHP file named `darkarch`; on a response containing `success:true` and `userid`, it assumes the upload is reachable at the plugin temporary-upload path as `darkarch.php`. The script accepts `-u/--url` for one target, or reads targets from `-f/--file` (default `list.txt`) and uses up to 50 threads in bulk mode. It disables TLS-certificate warnings and verification, forces `NO_PROXY=*`, performs a connectivity check against `https://1.1.1.1`, and records successful URLs in two local result files. Because `shell.php` is absent from the analyzed repository, the exact shell commands or C2 behavior cannot be determined; however, successful PHP upload and execution would permit the functionality embedded in an operator-supplied payload.
Repository contains a small exploit package for CVE-2025-6440 targeting the WordPress WooCommerce Designer Pro plugin. There are 3 files total: a Python exploit script, a Nuclei YAML template, and a README. Because the repository includes a Nuclei template, it appears framework-related, but the Python script is the main offensive component and the YAML is a safer detection/check template. The Python script CVE-2025-6440.py is a standalone unauthenticated arbitrary file upload exploit. It accepts a target base URL, generates a random uniq directory token, crafts a multipart/form-data POST to /wp-admin/admin-ajax.php with action=wcdp_save_canvas_design_ajax, and submits attacker-controlled file content. It then optionally verifies exploitation by requesting the uploaded file from /wp-content/uploads/wcdp-uploads/temp/<uniq>/<filename>. The default behavior uploads a benign .txt file for confirmation, but the script and README explicitly indicate the vulnerability could be used to upload malicious PHP and achieve RCE. The Nuclei template CVE-2025-6440.yaml performs a safe check using the same vulnerable AJAX endpoint and then verifies retrieval of a benign test file. This template is detection-oriented rather than full exploitation, but it confirms the same primitive: unrestricted unauthenticated upload. Notable implementation details: the Python exploit disables TLS certificate verification, uses a fixed multipart boundary, sets XMLHttpRequest-like headers, and checks for '"success":true' in the response body. No cleanup is automated; uploaded files remain on the server. Overall, the repository's purpose is to demonstrate and validate a critical web/network attack path that enables arbitrary file upload against vulnerable WooCommerce Designer Pro installations, with likely escalation to remote code execution if executable server-side files are accepted.
Repository contains a small exploit PoC set for CVE-2025-6440 with three files: a Python batch exploitation script, a Nuclei YAML template, and a README. The Python script is the operational exploit: it reads target base URLs from an input file, normalizes them, and sends multipart POST requests to the WordPress AJAX endpoint /wp-admin/admin-ajax.php using the action wcdp_save_canvas_design_ajax. It supplies crafted JSON parameters including a random uniq token and uploads a file named abc.php containing a minimal PHP payload that echoes 'RCE TEST'. After upload, it predicts the public file location under /wp-content/uploads/wcdp-uploads/temp/{uniq}/abc.php and performs a GET request to verify accessibility. The script supports multithreaded batch targeting via ThreadPoolExecutor and logs results to local files named success and failed. The YAML file is a Nuclei template rather than a full exploit payload; it performs a safer verification by uploading a PNG file to the same endpoint and then requesting /wp-content/uploads/wcdp-uploads/temp/{{uniq}}/pixel.png to confirm the vulnerability. Because a Nuclei template is present, this repository appears framework-related, but the Python file is still the main exploit artifact. Overall purpose: validate and exploit an unauthenticated arbitrary file upload in a WordPress plugin, with the Python PoC demonstrating potential RCE through PHP upload and the YAML template providing automated detection/verification.
This repository contains a small exploit kit for CVE-2025-6440, an unauthenticated arbitrary file upload vulnerability in the WooCommerce Designer Pro WordPress plugin up to version 1.9.26. The repo has 5 files: two Python scripts, one Nuclei template, one PHP payload, and a minimal README. Because the repository includes a Nuclei template, it is partly framework-oriented, but the repo also contains standalone exploit code. Structure and purpose: - CVE-2025-6440.yaml: Nuclei detection template. It performs a GET request to /wp-content/plugins/wc-designer-pro/readme.txt, extracts the Stable tag version, and confirms the plugin is present and <= 1.9.26. This file is for fingerprinting/detection only. - POC-CVE-2025-6440.py: Clean standalone proof-of-concept exploit. It targets /wp-admin/admin-ajax.php and submits a multipart POST with action=wcdp_save_canvas_design_ajax and crafted JSON params/files metadata. It uploads a tiny PNG and predicts the public path under /wp-content/uploads/wcdp-uploads/temp/{uniq}/{fname}, then checks whether the file is reachable. - CVE-2025-6440.py: Larger mass-exploitation script with threading and terminal UI. Although the provided content is truncated, the visible logic shows it is designed for bulk targeting from a list of URLs, tracks successes, and references shell.php as the upload payload. Based on filenames and variables, it likely uploads the PHP shell to multiple targets and records successful shell URLs. - shell.php: Not a benign test file; it is a staged PHP loader/backdoor. When executed, it fetches PHP content from a remote URL (default https://hirachi.jp//access/db.txt or attacker-supplied ?src= URL), writes it to a temporary file, stores the temp path in a cookie, and includes it. On later requests it re-includes the cached file. This turns successful file upload into practical remote code execution. - README.md: Minimal title only. Main exploit capability: The core exploit abuses the unauthenticated AJAX action wcdp_save_canvas_design_ajax to upload attacker-controlled files to a WordPress uploads path. The simple POC demonstrates arbitrary file upload with an image. The larger script appears intended for operational use against many targets and likely uploads shell.php for post-exploitation. If the server executes uploaded PHP, the included shell provides a persistent loader that can pull second-stage code from a remote host. Overall assessment: This is a real exploit repository, not just a detector. It includes both a detection template and active exploitation tooling. The Nuclei YAML is only for identifying vulnerable targets, while the Python scripts and PHP payload provide exploitation and post-upload execution capability. The presence of a remote-fetching PHP loader increases impact beyond a basic POC, making the repository operational rather than purely demonstrative.
Repository contains a single Python script (`main.py`) implementing an asynchronous, unauthenticated RCE exploiter targeting the WordPress plugin “WC Designer Pro” (`wc-designer-pro`). The tool uses aiohttp with high concurrency to process one or more input target lists, probes targets for (1) an expected response from `POST /wp-admin/admin-ajax.php` with `action=wcdp_save_canvas_design_ajax` and (2) the presence of the plugin asset `HEAD /wp-content/plugins/wc-designer-pro/assets/css/wcdp-design.min.css`. If checks indicate the plugin is present and likely vulnerable, it attempts exploitation by uploading a local `shell.php` via the same admin-ajax action (multipart form). On success it records the resulting webshell URL(s) to `resultshell.txt` and prints progress/summary using the Rich console UI. The script disables TLS certificate verification, supports configurable concurrency (default 50), and is designed for bulk scanning/exploitation of many WordPress sites.
Repository contains a single Python exploit script plus README and requirements. The exploit targets CVE-2025-6440: an unauthenticated arbitrary file upload in the WordPress WooCommerce Designer Pro / Canvas Designer plugin (<= 1.9.26), specifically the AJAX action `wcdp_save_canvas_design_ajax` handled via `wp-admin/admin-ajax.php`. Core behavior (CVE-2025-6440.py): - Normalizes the target base URL (adds scheme if missing). - Reads an attacker-provided local file (`--file`, typically a PHP webshell) and uploads it via `requests.post()` to `/wp-admin/admin-ajax.php` with form fields `action=wcdp_save_canvas_design_ajax` and a JSON `params` structure indicating file name/extension. - Uses a random `uniq` token (12 hex chars) to influence/track the upload path. - Attempts to parse the server JSON response to discover a returned public path/URL; if not found, it derives a predictable public URL under `/wp-content/uploads/wcdp-uploads/temp/{uniq}/{filename}`. - Performs a follow-up `GET` to the derived public URL to confirm the file is accessible, and performs basic content checks (PNG magic header; presence of PHP tags) to indicate whether a PHP payload may have been stored. Notable implementation details: - Disables TLS verification (`verify=False`) and suppresses urllib3 warnings. - Adds browser-like headers and `X-Requested-With: XMLHttpRequest`. - Does not automatically execute the uploaded payload; it only uploads and verifies accessibility/content. RCE depends on server-side execution of the uploaded PHP (e.g., if uploads directory allows PHP execution or if the file is placed in an executable location). Overall purpose: provide an operational PoC/exploit to achieve unauthenticated arbitrary file upload against vulnerable WordPress sites, enabling potential remote code execution by uploading a PHP payload and then accessing it via a predictable uploads path.
This repository provides multiple tools and templates for exploiting CVE-2025-6440, a critical vulnerability in the WordPress WCDP (WooCommerce Designer Pro) plugin that allows unauthenticated file upload via the 'wcdp_save_canvas_design_ajax' AJAX action. The repository includes: - A Nuclei template (CVE-2025-6440.yaml) for automated detection and exploitation, which uploads a PNG file and verifies its presence. - A mass exploitation script (mass-CVE-2025-6440.py) that uploads a PHP payload to multiple target URLs in parallel, reporting success or failure for each. - A proof-of-concept script (poc_CVE-2025-6440.py) that uploads a PHP web shell to a single target and provides a public URL for command execution. - A Dork.txt file with a Google dork to help identify potentially vulnerable sites. The main attack vector is network-based, targeting the '/wp-admin/admin-ajax.php' endpoint. Successful exploitation results in a PHP web shell being accessible at a predictable uploads path, allowing remote code execution. The repository is operational and provides both detection and exploitation capabilities.
This repository contains a working exploit for an unauthenticated remote code execution (RCE) vulnerability in the WC Designer Pro WordPress plugin (CVE-2025-XXXXX). The exploit is implemented in Python (poc-exploit.py) and automates the process of detecting the vulnerability, uploading a PHP web shell, and reporting successful exploitation. The exploit targets the /wp-admin/admin-ajax.php endpoint, abusing the 'wcdp_save_canvas_design_ajax' action to upload arbitrary PHP files without authentication. The presence of the plugin is verified by checking for a specific CSS file. Upon successful exploitation, a PHP shell is uploaded to a predictable path under /wp-content/uploads/wcdp-uploads/temp/darkarch/darkarch.php, allowing the attacker to execute arbitrary system commands via HTTP requests. The script supports multi-threaded exploitation of multiple targets, saves results to output files, and provides a rich command-line interface. The repository includes a README with detailed technical information, usage instructions, and statistics from previous exploitation runs. No fake or destructive code is present; the exploit is operational and provides a real web shell payload.
This repository contains a Python exploit script (CVE-2025-6440.py) targeting the WooCommerce Designer Pro WordPress plugin (versions <= 1.9.26), which is vulnerable to unauthenticated arbitrary file upload (CVE-2025-6440). The exploit is operational and enables mass exploitation by uploading a user-supplied PHP webshell (shell.php) to multiple targets listed in a file (list.txt). The script features a modern console UI using the 'rich' library, multi-threaded execution for speed, and robust error handling. Successful exploits are logged in 'success_results.txt' and 'uploaded_shells.txt'. The repository also includes a README with detailed usage instructions, a license file, and a requirements.txt listing Python dependencies. No hardcoded C2 or malicious endpoints are present; the only external HTTP request is to google.com for connectivity checks. The exploit is not part of a framework and is a standalone operational tool for remote code execution via webshell upload.
This repository contains a Python proof-of-concept exploit for CVE-2025-6440, a critical file upload vulnerability in the WooCommerce Designer Pro WordPress plugin (versions <=1.9.26). The exploit script (CVE-2025-6440.py) allows an attacker to upload an arbitrary file (such as a PHP webshell) to the target WordPress site's /wp-content/uploads/ directory by abusing the vulnerable wcdp_save_canvas_design_ajax AJAX action exposed at /wp-admin/admin-ajax.php. The script verifies the upload, attempts to extract any PHP code from the uploaded file, and saves it locally for confirmation. The repository also includes a README.md with usage instructions and mitigation advice, and a requirements.txt listing Python dependencies. The exploit is network-based, targeting a specific AJAX endpoint, and is operational as a proof-of-concept for remote code execution via file upload.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.