{"repo":"p0dalirius/Wordpress-webshell-plugin","free":true,"listed":false,"github":"https://github.com/p0dalirius/Wordpress-webshell-plugin","clone":"git clone https://github.com/p0dalirius/Wordpress-webshell-plugin.git","description":"A webshell plugin and interactive shell for pentesting a WordPress website.","language":"Python","stars":115,"topics":["plugin","webshell","wordpress"],"license":"MIT","category":"self-hosted-apps","readme_excerpt":"WordPress webshell plugin for RCE A webshell plugin and interactive shell for pentesting a WordPress website. Features - [x] Webshell plugin for WordPress. - [x] Execute system commands via an API with ?action=exec . - [x] Download files from the remote system to your attacking machine with ?action=download . Usage Requirements : You need to have the credentials of the admin account of the WordPress website. Step 1: Upload the webshell plugin First, login with admin rights on the WordPress website and go to \" Plugins -- Add New \" page, at http://127.0.0.1:10080/wordpress/wp-admin/plugin-install.php, and click on \"Upload Plugin\": Upload the plugin, and click on \" Activate the plugin \": Step 2.1: Executing commands You can now execute commands by sending a GET or POST request to 127.0.0.1:10080/wordpress/wp-content/plugins/wp webshell/wp webshell.php with action=exec&cmd=id : You can also access it by a GET request from a browser: Step 2.2: Downloading files You can also download remote files by sending a GET or POST request to 127.0.0.1:10080/wordpress/wp-content/plugins/wp webshell/wp webshell.php with action=download&cmd=/etc/passwd : You can also download a remote file from a browser with a GET request : Step 3: The interactive console When your webshell is active, you can now use the interactive console.py to execute commands and download remote files. https://user-images.githubusercontent.com/79218792/169876672-7ecd50a4-21f8-47d3-a575-ff2b81b5ec22.mp4 References - https:/","default_branch":null,"files":null,"tree":[],"storefront":"/r/p0dalirius","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/p0dalirius/Wordpress-webshell-plugin/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}