针对 CVE-2023-47504 的利用程序。
根据 NIST 的描述,该漏洞应允许未经身份验证的用户访问 Elementor Website Builder 插件中的功能。
根据我对该漏洞的研究,以及从描述该漏洞的 Patchstack URL 来判断:https://patchstack.com/database/vulnerability/elementor/wordpress-elementor-plugin-3-16-4-contributor-arbitrary-attachment-read-vulnerability?_s_id=cve,我认为这实际上需要至少一个订阅者账户的凭据。
此外,要使漏洞利用生效,需要访问目标网站的 wp-config.php 文件。
wp-config.phpwp-admin/profile.php 并更新你的个人资料;wordpress_logged_in_* cookie 和你的用户 ID;wp-config.php 的 NONCE_KEY + NONCE_SALT 字符串;python exploit.py --target <TARGET> --wordpress-cookie <COPIED COOKIE> --uid <COPIED USER ID> --salt <COPIED SALT>;/wp-content/uploads/elementor/css 下的文件);