Skip to content
KitploitKITPLOIT
ИнструментыЭксплойтыБлог
Log in
Отправить
ИнструментыЭксплойтыБлог
Отправить

Инструменты для хакинга, пентеста и кибербезопасности — ваш арсенал защиты!

Kitploit — это каталог инструментов для хакинга, кибербезопасности и пентестинга. Находите последние обновления проектов для поиска уязвимостей, анализа систем, автоматизации тестирования и усиления вашей безопасности.

ЛентыКонтактыКонфиденциальность© 2026 Kitploit

Каталог инструментов

Категории

Все категории
Loading categories
CVE-2026-81294 — Proof-of-concept and lab reproduction for CVE-2026-81294, an unauthenticated privilege escalation in the WordPress Authorizer plugin via unverified OAuth2 email matching. | Kitploit
Инструменты/GitHubGitHub/abraxas/cve-2026-81294
Privilege EscalationVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingAuthenticationLabs & Practice
GitHubabraxas/cve-2026-81294

CVE-2026-81294

Proof-of-concept and lab reproduction for CVE-2026-81294, an unauthenticated privilege escalation in the WordPress Authorizer plugin via unverified OAuth2 email matching.

311910 дней назадЕщё не проверено

Популярное

Смотреть все →

Откройте для себя самые используемые инструменты нашего сообщества.

Изучить все инструменты

Просмотрите нашу коллекцию инструментов

Смотреть все инструменты →
Поделиться
Репозиторий
Контент недоступен на запрошенном языке. Показываем английскую версию.

Abraxas Labs - CVE-2026-81294

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-81294

CVE-2026-81294

Authorizer 3.15.1 - Paul Ryan

I am @abraxas_null. Loopback lab. The client is CVE-2026-81294-Abraxas-Labs.py.

Unverified email is enough. 3.15.1 maps GitHub emails[] to entry.email without checking entry.verified. Generic OAuth2 has the same hole. HTTP is GET /wp-login.php?external=oauth2, not admin-ajax. If that email matches an admin, Authorizer sets the cookie. 3.15.2 filters empty entry.verified for GitHub and adds oauth2_require_verified_email for generic.

CVECVE-2026-81294 · CVE.org
CWECWE-266
CVSSCritical: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ProductWordPress - Authorizer
Affectedall versions through 3.15.1 (inclusive)
Patched3.15.2 and later
Authnone
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

Register an OAuth identity whose unverified email is the site admin's. Complete the login redirect. You are that admin. The lab uses a loopback mock and a display name witness.


How I found it

Patchstack named unverified GitHub emails. I read the GitHub /emails map, then ran the same missing check on generic OAuth2 against a loopback mock.

GET /wp-login.php?external=oauth2 with a cookie jar. Follow 302s. GET /?auth_lab=1. Witness POCWitness81294.

Wrong turns: POST action=oauth2 at admin-ajax.php (login HTML, no cookie); dropping PHPSESSID between authorize and callback; token URL not reachable from PHP; oauth2_email_not_verified on 3.15.2; empty_username when the email did not map.


The lab

Port 8088. Authorizer 3.15.1. oauth2=1 generic mock. Admin email [email protected], display_name POCWitness81294.

  • lab/Dockerfile
  • lab/docker-compose.override.yml
  • lab/docker-compose.yml

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-81294-Abraxas-Labs.py

Witness: GET /?auth_lab=1 after OAuth is POCWitness81294. Login page HTML without that string is not it.

Ways to lose without learning anything:

  • login form 200 without cookie
  • oauth2_email_not_verified
  • empty_username
  • reverse shell

The fix

Update Authorizer to 3.15.2 or newer. Re-run CVE-2026-81294-Abraxas-Labs.py against the patched build: POCWitness81294 must not appear.


References

  • CVE-2026-81294 · NVD

  • CVE-2026-81294 · CVE.org

  • patchstack.com/database/wordpress/plugin/authorizer/vulnerability/wordpress-authorizer-plugin-3-15-1-privilege-escalation-vulnerability?_s_id=cve

  • github.com/advisories/GHSA-xppg-27gw-vxcj

  • nvd.nist.gov/vuln/detail/CVE-2026-81294

  • Plugin directory: authorizer

  • Trac browser: plugins.trac.wordpress.org/authorizer

  • SVN tags: plugins.svn.wordpress.org/authorizer

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

Скачать инструмент