Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

फ़ीडसंपर्कगोपनीयता© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
CVE-2026-81294 — Proof-of-concept and lab reproduction for CVE-2026-81294, an unauthenticated privilege escalation in the WordPress Authorizer plugin via unverified OAuth2 email matching. | Kitploit
उपकरण/GitHubGitHub/abraxas/cve-2026-81294
Privilege EscalationVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingAuthenticationLabs & Practice
GitHubabraxas/cve-2026-81294

CVE-2026-81294

Proof-of-concept and lab reproduction for CVE-2026-81294, an unauthenticated privilege escalation in the WordPress Authorizer plugin via unverified OAuth2 email matching.

311910 दिन पहलेअभी तक समीक्षित नहीं

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
रिपॉजिटरी देखें
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

Abraxas Labs - CVE-2026-81294

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-81294

CVE-2026-81294

Authorizer 3.15.1 - Paul Ryan

I am @abraxas_null. Loopback lab. The client is CVE-2026-81294-Abraxas-Labs.py.

Unverified email is enough. 3.15.1 maps GitHub emails[] to entry.email without checking entry.verified. Generic OAuth2 has the same hole. HTTP is GET /wp-login.php?external=oauth2, not admin-ajax. If that email matches an admin, Authorizer sets the cookie. 3.15.2 filters empty entry.verified for GitHub and adds oauth2_require_verified_email for generic.

CVECVE-2026-81294 · CVE.org
CWECWE-266
CVSSCritical: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ProductWordPress - Authorizer
Affectedall versions through 3.15.1 (inclusive)
Patched3.15.2 and later
Authnone
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

Register an OAuth identity whose unverified email is the site admin's. Complete the login redirect. You are that admin. The lab uses a loopback mock and a display name witness.


How I found it

Patchstack named unverified GitHub emails. I read the GitHub /emails map, then ran the same missing check on generic OAuth2 against a loopback mock.

GET /wp-login.php?external=oauth2 with a cookie jar. Follow 302s. GET /?auth_lab=1. Witness POCWitness81294.

Wrong turns: POST action=oauth2 at admin-ajax.php (login HTML, no cookie); dropping PHPSESSID between authorize and callback; token URL not reachable from PHP; oauth2_email_not_verified on 3.15.2; empty_username when the email did not map.


The lab

Port 8088. Authorizer 3.15.1. oauth2=1 generic mock. Admin email [email protected], display_name POCWitness81294.

  • lab/Dockerfile
  • lab/docker-compose.override.yml
  • lab/docker-compose.yml

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-81294-Abraxas-Labs.py

Witness: GET /?auth_lab=1 after OAuth is POCWitness81294. Login page HTML without that string is not it.

Ways to lose without learning anything:

  • login form 200 without cookie
  • oauth2_email_not_verified
  • empty_username
  • reverse shell

The fix

Update Authorizer to 3.15.2 or newer. Re-run CVE-2026-81294-Abraxas-Labs.py against the patched build: POCWitness81294 must not appear.


References

  • CVE-2026-81294 · NVD

  • CVE-2026-81294 · CVE.org

  • patchstack.com/database/wordpress/plugin/authorizer/vulnerability/wordpress-authorizer-plugin-3-15-1-privilege-escalation-vulnerability?_s_id=cve

  • github.com/advisories/GHSA-xppg-27gw-vxcj

  • nvd.nist.gov/vuln/detail/CVE-2026-81294

  • Plugin directory: authorizer

  • Trac browser: plugins.trac.wordpress.org/authorizer

  • SVN tags: plugins.svn.wordpress.org/authorizer

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

टूल डाउनलोड करें