Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

الخلاصاتاتصالالخصوصية© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2026-81294 — Proof-of-concept and lab reproduction for CVE-2026-81294, an unauthenticated privilege escalation in the WordPress Authorizer plugin via unverified OAuth2 email matching. | Kitploit
أدوات/GitHubGitHub/abraxas/cve-2026-81294
Privilege EscalationVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingAuthenticationLabs & Practice
GitHubabraxas/cve-2026-81294

CVE-2026-81294

Proof-of-concept and lab reproduction for CVE-2026-81294, an unauthenticated privilege escalation in the WordPress Authorizer plugin via unverified OAuth2 email matching.

3119منذ 10 أياملم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
عرض المستودع
المحتوى غير متوفر باللغة المطلوبة. عرض النسخة الإنجليزية.

Abraxas Labs - CVE-2026-81294

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-81294

CVE-2026-81294

Authorizer 3.15.1 - Paul Ryan

I am @abraxas_null. Loopback lab. The client is CVE-2026-81294-Abraxas-Labs.py.

Unverified email is enough. 3.15.1 maps GitHub emails[] to entry.email without checking entry.verified. Generic OAuth2 has the same hole. HTTP is GET /wp-login.php?external=oauth2, not admin-ajax. If that email matches an admin, Authorizer sets the cookie. 3.15.2 filters empty entry.verified for GitHub and adds oauth2_require_verified_email for generic.

CVECVE-2026-81294 · CVE.org
CWECWE-266
CVSSCritical: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ProductWordPress - Authorizer
Affectedall versions through 3.15.1 (inclusive)
Patched3.15.2 and later
Authnone
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

Register an OAuth identity whose unverified email is the site admin's. Complete the login redirect. You are that admin. The lab uses a loopback mock and a display name witness.


How I found it

Patchstack named unverified GitHub emails. I read the GitHub /emails map, then ran the same missing check on generic OAuth2 against a loopback mock.

GET /wp-login.php?external=oauth2 with a cookie jar. Follow 302s. GET /?auth_lab=1. Witness POCWitness81294.

Wrong turns: POST action=oauth2 at admin-ajax.php (login HTML, no cookie); dropping PHPSESSID between authorize and callback; token URL not reachable from PHP; oauth2_email_not_verified on 3.15.2; empty_username when the email did not map.


The lab

Port 8088. Authorizer 3.15.1. oauth2=1 generic mock. Admin email [email protected], display_name POCWitness81294.

  • lab/Dockerfile
  • lab/docker-compose.override.yml
  • lab/docker-compose.yml

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-81294-Abraxas-Labs.py

Witness: GET /?auth_lab=1 after OAuth is POCWitness81294. Login page HTML without that string is not it.

Ways to lose without learning anything:

  • login form 200 without cookie
  • oauth2_email_not_verified
  • empty_username
  • reverse shell

The fix

Update Authorizer to 3.15.2 or newer. Re-run CVE-2026-81294-Abraxas-Labs.py against the patched build: POCWitness81294 must not appear.


References

  • CVE-2026-81294 · NVD

  • CVE-2026-81294 · CVE.org

  • patchstack.com/database/wordpress/plugin/authorizer/vulnerability/wordpress-authorizer-plugin-3-15-1-privilege-escalation-vulnerability?_s_id=cve

  • github.com/advisories/GHSA-xppg-27gw-vxcj

  • nvd.nist.gov/vuln/detail/CVE-2026-81294

  • Plugin directory: authorizer

  • Trac browser: plugins.trac.wordpress.org/authorizer

  • SVN tags: plugins.svn.wordpress.org/authorizer

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

تنزيل الأداة