Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2026-75816 — 针对 CVE-2026-75816 的概念验证与实验环境复现,该漏洞是通过 admin-ajax 表单提交实现的未认证 WordPress Frontend Admin 账户接管。 | Kitploit
工具/GitHubGitHub/abraxas/cve-2026-75816
漏洞分析漏洞利用Web应用程序漏洞利用Web安全渗透测试身份验证实验室与实践
GitHubabraxas/cve-2026-75816

CVE-2026-75816

针对 CVE-2026-75816 的概念验证与实验环境复现,该漏洞是通过 admin-ajax 表单提交实现的未认证 WordPress Frontend Admin 账户接管。

查看仓库
233天前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

Abraxas Labs - CVE-2026-75816

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-75816

CVE-2026-75816

Frontend Admin by DynamiApps 3.29.11 - shabti

我是 @abraxas_null。回环实验环境。客户端是 CVE-2026-75816-Abraxas-Labs.py。

user_1 不是一个文章(post)。未认证的 admin-ajax.php frontend_admin/form_submit。当对象 id 为非数字(user_1)时,ActionPost::conditions_logic() 会提前返回,从而跳过 current_user_can('edit_post')。在 3.29.11 中,Email 字段的 pre_update_value 没有 edit_user 检查,并且会 wp_update_user 更新用户 1 的邮箱。NVD 列出到 3.29.12;变更日志显示 3.29.12 添加了该检查。实验环境为 3.29.11。当前版本为 3.29.13。

CVECVE-2026-75816 · CVE.org
CWECWE-287
CVSS严重:9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
产品Frontend Admin by DynamiApps
受影响所有版本 至 3.29.11(NVD 列出 3.29.12;3.29.12 添加了 Email 字段的 edit_user 检查)
已修复3.29.12 及更高版本
认证无
许可证GNU Affero GPL v3.0
实验环境仅 127.0.0.1

攻击者能做什么

访客 POST 更改管理员邮箱。向该地址重置密码即可接管账户。实验环境止步于邮箱更改。我不会打印针对他人管理员的找回密码配方。


我是如何发现的

Wordfence 提到了 pre_update_value 和 user_1。我阅读了 conditions_logic,然后是 Email 字段,接着采集了公开表单。

GET /fea-lab/。提取 _acf_nonce、_acf_objects、user_email 字段键。POST acff[post][<key>][email protected]。GET /?fea_lab_email=1。小型 ajax JSON Post updated,然后是新的地址。

走过的弯路:action=pre_update_value 或 parse_array(函数名不是路由);硬编码 nonce;数字型 post_id(那样 edit_post 会真正执行,访客会被拒绝);who_can_see 不是 all;3.29.12;把请求体中仍然存在的 [email protected] 当作成功。


实验环境

端口 8088。Frontend Admin 3.29.11。公开表单 /fea-lab/,who_can_see=all,对象 user_1。

  • lab/Dockerfile
  • lab/docker-compose.override.yml
  • lab/docker-compose.yml
  • lab/run.sh

目标 仅限 127.0.0.1:8088(或你绑定的回环地址)。

cd lab
docker compose up --force-recreate
./run.sh

见证:GET /?fea_lab_email=1 为 [email protected]。通用表单 HTML 或 [email protected] 不算。

毫无收获的失败方式:

  • [email protected] 仍是管理员邮箱
  • admin-ajax 返回 0 / -1 / 权限 JSON,但没有邮箱更改
  • 反弹 shell
  • 向攻击者邮箱进行真实的密码重置

修复

将 Frontend Admin by DynamiApps 更新到 3.29.12 或更高版本(当前 3.29.13)。对已修补版本重新运行 CVE-2026-75816-Abraxas-Labs.py:管理员邮箱必须不变。


参考资料

  • CVE-2026-75816 · NVD

  • CVE-2026-75816 · CVE.org

  • plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.10/main/frontend/fields/user/class-user-email.php#L127

  • plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.10/main/frontend/forms/actions/post.php#L1001

  • plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.10/main/frontend/forms/actions/post.php#L1224

  • plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.10/main/frontend/forms/classes/display.php#L26

  • plugins.trac.wordpress.org/browser/acf-frontend-form-element/tags/3.29.10/main/frontend/forms/classes/submit.php#L125

  • plugins.trac.wordpress.org/changeset/3664865/acf-frontend-form-element

  • www.wordfence.com/threat-intel/vulnerabilities/id/f1637a3b-7b0f-485d-9d19-4f711f8c671b?source=cve

  • github.com/advisories/GHSA-pv54-wq7v-wf7v

  • nvd.nist.gov/vuln/detail/CVE-2026-75816

  • 插件目录:acf-frontend-form-element

  • Trac 浏览器:plugins.trac.wordpress.org/acf-frontend-form-element

  • SVN 标签:plugins.svn.wordpress.org/acf-frontend-form-element

  • Abraxas Labs:abraxaslabs.tech · github.com/abraxas · @abraxas_null


许可证

GNU Affero GPL v3.0。参见 LICENSE。


该客户端仅与回环地址通信。将其用于你并不拥有的系统,未获 Abraxas Labs 授权。无任何担保。

abraxaslabs.tech · github.com/abraxas · @abraxas_null

下载工具