CVE-2023-54352

CRITICAL

WP Travel Kit Travelscape - WordPress Seotheme Remote Code Execution Unauthenticated

Title source: rule
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-54352. PoCs published by Milad karimi.

AI-analyzed exploit summary This exploit targets a WordPress plugin/theme vulnerability (CVE-2023-54352) to achieve unauthenticated remote code execution by uploading a malicious PHP shell. It checks for the presence of a specific file (`mar.php`) in vulnerable paths and writes successful targets to output files.

Description

WordPress Seotheme contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by uploading malicious files to the theme directory. Attackers can access the uploaded PHP shell at /wp-content/themes/seotheme/mar.php to execute system commands and upload additional files for persistent access.

Exploits (1)

exploitdb WORKING POC
by Milad karimi · pythonwebappsphp
https://www.exploit-db.com/exploits/51789

This exploit targets a WordPress plugin/theme vulnerability (CVE-2023-54352) to achieve unauthenticated remote code execution by uploading a malicious PHP shell. It checks for the presence of a specific file (`mar.php`) in vulnerable paths and writes successful targets to output files.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: WordPress with Seotheme plugin/theme
No auth needed
Prerequisites: List of target URLs in a text file · Vulnerable WordPress installation with Seotheme plugin/theme
devstral-2 · analyzed Jun 08, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit exploit
ExploitDB-51789
https://www.exploit-db.com/exploits/51789
Third Party Advisory third-party-advisory
VulnCheck Advisory: WordPress Seotheme Remote Code Execution Unauthenticated
https://www.vulncheck.com/advisories/wordpress-seotheme-remote-code-execution-unauthenticated

Scores

CVSS v3 9.8
EPSS 0.0061
EPSS Percentile 44.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-306
Status published
Products (1)
WP Travel Kit/Travelscape 1.0.3
Published Jun 08, 2026
Tracked Since Jun 08, 2026