Skip to content

Dooztoria/Wordpress-Shell-Uploader

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

16 Commits
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

Dooz Header

Worpress Shell Deployer

Version Platform Type Maintained

About β€’ Gallery β€’ Features β€’ Capabilities β€’ Output β€’ Contact


♨️ About

WPAUTO is a specialized software engineered with a singular objective: gaining access to one of the largest CMS platforms globallyβ€”WordPress. This tool automates the process of shell uploading and persistence, bringing you full webshell access through intelligent detection and multiple injection vectors.

Disclaimer: This tool is intended for security research and educational purposes only. The authors are not responsible for any misuse of this software.


πŸ“Έ Gallery & Demo

Main Interface
Main Interface
Scanning Process
Scanning Process
Shell Injection
Injection
Admin Creation
Result

πŸŽ₯ Watch Demo Preview

Note: If the video does not load, click here to download.


⚑ Key Features

Feature Description
[+] 14+ Upload Methods Extensive array of injection vectors maximizing success rates.
[#] Security Bypass Auto-detection and bypass for 20+ Security Plugins (Wordfence, Sucuri, etc.).
[*] Smart Capability Parallel detection scanning to identify the best injection path automatically.
[@] Persistence Mode Auto-deployment of multiple backup shells and backdoor users.
[$] Credential Handler Supports 4 Credential Formats and Auto-Password Change functionality.
[>] High Performance Dual Terminal Architecture with unlimited threading support.

πŸ—Ό Capabilities & Modules

πŸ“€ Upload Vectors (14 Total)

WPAUTO employs a diverse range of methods to ensure payload delivery:

  • [THEME UPLOAD] ZIP Shell Injection
  • [PLUGIN UPLOAD] ZIP Shell Injection
  • [FILE MANAGER] Upload / Create / Edit
  • [MU-PLUGINS] Stealth Auto-Execute
  • [THEME EDITOR] Obfuscated Code Injection
  • [PLUGIN EDITOR] Obfuscated Code Injection
  • [MEDIA UPLOAD] Multi-extension Bypass
  • [REST API] /wp-json Endpoint Bypass
  • [XML-RPC] Legacy API Bypass
  • [SNIPPET] WPCode / CodeSnippets Exploitation
  • [HTACCESS] PHP Handler Manipulation
  • [WIDGET] Sidebar Injection
  • [IMPORTER] WXR Exploitation

πŸ›‘οΈ Defense Evasion

Auto-Disable & Bypass for major security suites:

  • Wordfence, Sucuri, iThemes, AIOS
  • Cerber, NinjaFirewall, Jetpack
  • Defender, Shield, BulletProof, Hide My WP
  • ...and more.

Obfuscation Engine:

  • 8 Variants of obfuscated injection code.
  • Designed to appear as legitimate WordPress core code.
  • Low detection rate against static scanners.

♾️ Persistence

Ensure long-term access with:

  • [ADMIN CREATOR] Automatically spawns a hidden administrator user.
  • [PASSWORD CHANGER] Rotates credentials for continued access.
  • [BACKUP SHELLS] Plants multiple access points across the directory.

πŸ’» System Architecture

WPAUTO utilizes a Dual Terminal Architecture to decouple interface rendering from processing logic, ensuring maximum stability during high-volume threading.

Architecture Diagram
  • Main Terminal: Handles UI, config parsing, and result aggregation.

  • Worker Terminal: dedicated process for unlimited multi-threading and connection handling.

  • Configurable: Full control via config.ini.

  • Compatibility: Multi-device support.


πŸ“ Output Structure

Results are organized systematically for easy retrieval:

/Output
β”œβ”€β”€ shell.txt                  # Successful shell URLs
β”œβ”€β”€ theme_uploaded.txt         # Via Theme method
β”œβ”€β”€ plugin_uploaded.txt        # Via Plugin method
β”œβ”€β”€ muplugins_uploaded.txt     # Via Must-Use Plugins
β”œβ”€β”€ filemanager_uploaded.txt   # Via File Manager
β”œβ”€β”€ editor_injected.txt        # Via Editor Injection
β”œβ”€β”€ admin_created.txt          # Created Admin Credentials
└── password_changed.txt       # Rotated Credentials


πŸ“© Contact & Support

For access, updates, and inquiries:

πŸ₯ Official Channel: t.me/Dooztoria


DOOZTORIA β€’ WPAUTO Β© 2025

About

🍣 The Art of Automating Access. WordPress Exploitation Suite. 🌊⚑

Topics

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published