willygailo/CVE-2026-3891-Linux
GitHub: willygailo/CVE-2026-3891-Linux
针对CVE-2026-3891漏洞的利用工具。
Stars: 1 | Forks: 0
```
███████╗██████╗ ██╗███████╗███╗ ██╗██████╗ ███████╗
██╔════╝██╔══██╗██║██╔════╝████╗ ██║██╔══██╗██╔════╝
█████╗ ██████╔╝██║█████╗ ██╔██╗ ██║██║ ██║███████╗
██╔══╝ ██╔══██╗██║██╔══╝ ██║╚██╗██║██║ ██║╚════██║
██║ ██║ ██║██║███████╗██║ ╚████║██████╔╝███████║
╚═╝ ╚═╝ ╚═╝╚═╝╚══════╝╚═╝ ╚═══╝╚═════╝ ╚══════╝
```
```
███████╗██╗ ██╗██████╗ ██╗ ██████╗ ██╗████████╗
██╔════╝╚██╗██╔╝██╔══██╗██║ ██╔═══██╗██║╚══██╔══╝
█████╗ ╚███╔╝ ██████╔╝██║ ██║ ██║██║ ██║
██╔══╝ ██╔██╗ ██╔═══╝ ██║ ██║ ██║██║ ██║
███████╗██╔╝ ██╗██║ ███████╗╚██████╔╝██║ ██║
╚══════╝╚═╝ ╚═╝╚═╝ ╚══════╝ ╚═════╝ ╚═╝ ╚═╝
```
# 🛡️ FriendsExploit — CVE-2026-3891
### `Pix for WooCommerce <= 1.5.0 — Unauthenticated Arbitrary File Upload`
---





---
## 📖 Description
> ⚡ This tool exploits **CVE-2026-3891**, a critical **unauthenticated arbitrary file upload** vulnerability found in the **Pix for WooCommerce** WordPress plugin (versions ≤ 1.5.0).
An unauthenticated attacker can upload arbitrary files (e.g., PHP web shells) to the target server **without any authentication**, leading to **Remote Code Execution (RCE)**.
> ⚠️ **DISCLAIMER**
>
> This tool is intended for **authorized penetration testing and educational purposes only**.
> Do not use this tool against systems you do not own or have explicit written permission to test.
> **Unauthorized use is illegal.**
---
## 🔍 CVE Details
| 🆔 CVE ID | CVE-2026-3891 |
| 🔌 Plugin | Pix for WooCommerce |
| 🎯 Affected | Versions ≤ 1.5.0 |
| 🔓 Type | Unauthenticated Arbitrary File Upload |
| 💥 Impact | Remote Code Execution (RCE) |
| ⚠️ CVSS | Critical |
| # | Step | Description |
|---|---|---|
| 1 | 🎯 Targets | Enter target URL(s) comma-separated or browse to a .txt file |
| 2 | 🐚 Shell File (.php) | Enter the PHP shell filename (default: shell.php) |
| 3 | 📄 Output File | Specify output file for successful shells (default: shells.txt) |
| 4 | 🧵 Threads | Set number of concurrent threads (max: 50) |
| 5 | ▶️ Start Exploit | Click to begin the exploitation process |
| 6 | ⏹️ Stop | Click to halt execution at any time |
| 7 | 🧹 Clear Log | Click to clear the output log |
WILLY JR. CARNASA GAILO 🔬 Security Researcher 💻 Developer & Exploit Author |
|
|
|
|
|
|
|
|
> 🎯 Sa lahat ng **bug bounty hunters** at **security researchers** na nagpo-propose ng responsible disclosure — kayo ang dahilan kung bakit nag-i-improve ang security ng mga web applications. > > 🙏 Kung may naitulong itong tool sa iyong **authorized penetration testing**, please consider giving back sa open-source security community. ---
### 📜 Legal Notice
```
╔═══════════════════════════════════════════════════════════════╗
║ ║
║ This tool is for AUTHORIZED penetration testing only. ║
║ Always follow responsible disclosure practices. ║
║ Unauthorized use is ILLEGAL and may result in prosecution. ║
║ ║
╚═══════════════════════════════════════════════════════════════╝
```
---
### 📊 Repository Stats

---
**© 2026 FriendsExploit | Developed by Willy Jr. Carnasa Gailo**
Made with 🛡️ for the security community
标签:CVE-2026-3891, Pix for WooCommerce, WordPress 安全, WordPress 插件, 任意文件上传, 威胁模拟, 安全事件响应, 安全测试, 安全漏洞, 安全漏洞分析, 安全漏洞报告, 安全防护, 插件安全, 攻击性安全, 未授权访问, 漏洞修复, 网络安全, 网络安全培训, 逆向工具, 隐私保护, 黑客技术