0-Day RCE Exploit for an OpenCart Plugin for Sale
Dark Web2026-08-07, 10:10
0-Day RCE Exploit for an OpenCart Plugin for Sale
For informational purposes only.
Vulnerability type: Arbitrary File Upload / Arbitrary File Delete → RCE
Price: Auction (starting bid — $3,000, minimum increment — $1,000, buyout — $10,000)
Price: Auction (starting bid — $3,000, minimum increment — $1,000, buyout — $10,000)
The author claims to be selling an exploit for an OpenCart plugin that allows arbitrary file upload and deletion on the server without any stated restrictions. According to the seller, a single POST request is enough to obtain a shell, meaning the vulnerability could potentially be used to achieve remote code execution on the e-commerce server.
As proof, the author provides a demonstration showing a file being uploaded to a test server and then accessed through the web interface.
The seller also states that the extension has around 19,000 installs from the official OpenCart Marketplace, representing a significant user base for a single plugin.
OpenCart — a popular open-source CMS for online stores, especially in the small and medium e-commerce segment. According to BuiltWith, there are about 190 thousand active sites on OpenCart worldwide and more than 922 thousand sites that have used the platform historically.
Vendors
Products