Skip to content
KitploitKITPLOIT
HerramientasExploitsBlog
Log in
Enviar
HerramientasExploitsBlog
Enviar

¡Herramientas de Hacking, PenTest y Ciberseguridad para tu Arsenal de Seguridad!

Kitploit es un directorio de herramientas de hacking, ciberseguridad y pentesting. Descubre las últimas actualizaciones de proyectos para encontrar vulnerabilidades, analizar sistemas, automatizar pruebas y fortalecer tu seguridad.

FeedsContactoPrivacidad© 2026 Kitploit

Directorio de Herramientas

Categorías

Ver todas las categorías
Loading categories
CVE-2026-81294 — Proof-of-concept and lab reproduction for CVE-2026-81294, an unauthenticated privilege escalation in the WordPress Authorizer plugin via unverified OAuth2 email matching. | Kitploit
Herramientas/GitHubGitHub/abraxas/cve-2026-81294
Privilege EscalationVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingAuthenticationLabs & Practice
GitHubabraxas/cve-2026-81294

CVE-2026-81294

Proof-of-concept and lab reproduction for CVE-2026-81294, an unauthenticated privilege escalation in the WordPress Authorizer plugin via unverified OAuth2 email matching.

3119hace 10 díasAún no revisado

Más Populares

Ver todos →

Descubre las herramientas más usadas por nuestra comunidad.

Explora todas las herramientas

Explora nuestra colección de herramientas

Ver todas las herramientas →
Compartir
Ver Repositorio
Contenido no disponible en el idioma solicitado. Mostrando versión en inglés.

Abraxas Labs - CVE-2026-81294

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-81294

CVE-2026-81294

Authorizer 3.15.1 - Paul Ryan

I am @abraxas_null. Loopback lab. The client is CVE-2026-81294-Abraxas-Labs.py.

Unverified email is enough. 3.15.1 maps GitHub emails[] to entry.email without checking entry.verified. Generic OAuth2 has the same hole. HTTP is GET /wp-login.php?external=oauth2, not admin-ajax. If that email matches an admin, Authorizer sets the cookie. 3.15.2 filters empty entry.verified for GitHub and adds oauth2_require_verified_email for generic.

CVECVE-2026-81294 · CVE.org
CWECWE-266
CVSSCritical: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ProductWordPress - Authorizer
Affectedall versions through 3.15.1 (inclusive)
Patched3.15.2 and later
Authnone
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

Register an OAuth identity whose unverified email is the site admin's. Complete the login redirect. You are that admin. The lab uses a loopback mock and a display name witness.


How I found it

Patchstack named unverified GitHub emails. I read the GitHub /emails map, then ran the same missing check on generic OAuth2 against a loopback mock.

GET /wp-login.php?external=oauth2 with a cookie jar. Follow 302s. GET /?auth_lab=1. Witness POCWitness81294.

Wrong turns: POST action=oauth2 at admin-ajax.php (login HTML, no cookie); dropping PHPSESSID between authorize and callback; token URL not reachable from PHP; oauth2_email_not_verified on 3.15.2; empty_username when the email did not map.


The lab

Port 8088. Authorizer 3.15.1. oauth2=1 generic mock. Admin email [email protected], display_name POCWitness81294.

  • lab/Dockerfile
  • lab/docker-compose.override.yml
  • lab/docker-compose.yml

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-81294-Abraxas-Labs.py

Witness: GET /?auth_lab=1 after OAuth is POCWitness81294. Login page HTML without that string is not it.

Ways to lose without learning anything:

  • login form 200 without cookie
  • oauth2_email_not_verified
  • empty_username
  • reverse shell

The fix

Update Authorizer to 3.15.2 or newer. Re-run CVE-2026-81294-Abraxas-Labs.py against the patched build: POCWitness81294 must not appear.


References

  • CVE-2026-81294 · NVD

  • CVE-2026-81294 · CVE.org

  • patchstack.com/database/wordpress/plugin/authorizer/vulnerability/wordpress-authorizer-plugin-3-15-1-privilege-escalation-vulnerability?_s_id=cve

  • github.com/advisories/GHSA-xppg-27gw-vxcj

  • nvd.nist.gov/vuln/detail/CVE-2026-81294

  • Plugin directory: authorizer

  • Trac browser: plugins.trac.wordpress.org/authorizer

  • SVN tags: plugins.svn.wordpress.org/authorizer

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

Descargar herramienta