¡¾Îó²îͨ¸æ¡¿WordPress Easy WP SMTP²å¼þ0 dayÎó²î
Ðû²¼Ê±¼ä 2020-12-150x00 Îó²î¸ÅÊö
CVE ID | ÔÝÎÞ | ʱ ¼ä | 2020-12-15 |
Àà ÐÍ | Éè¼Æ¹ýʧ | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ÊÇ | Ó°Ïì¹æÄ£ | 1.4.2¼°Ö®Ç°°æ±¾ |
0x01 Îó²îÏêÇé

WordPressÊÇʹÓÃPHP¿ª·¢µÄ²©¿Íƽ̨£¬Óû§¿ÉÒÔÔÚÖ§³ÖPHPºÍMySQLÊý¾Ý¿âµÄ·þÎñÆ÷ÉϼÜÉèÊôÓÚ×Ô¼ºµÄÍøÕ¾£¬Ò²¿ÉÒÔ°Ñ WordPress¿´³ÉÒ»¸öÄÚÈݹÜÀíϵͳ£¨CMS£©À´Ê¹Óá£WordPress Easy WP SMTPÊÇÒ»¸ödzÒ×µÄWP SMTP²å¼þ£¬×°Öúó¿ÉÒÔÉèÖò¢Í¨¹ýSMTP·þÎñÆ÷·¢Ë͵ç×ÓÓʼþ¡£
¿ËÈÕ£¬WordPress ÐÞ¸´ÁËEasy WP SMTP²å¼þÖеÄÒ»¸ö0dayÎó²î£¬¹¥»÷Õß¿ÉÒÔʹÓøÃÎó²îÖØÖùÜÀíÔ±ÃÜÂë¡¢ÔÚ²©¿ÍÉÏ×°ÖÃÁ÷Ã¥²å¼þµÈ¡£ÏÖÔÚ£¬¸Ã²å¼þ±»×°ÖÃÔÚ500,000¶à¸öÕ¾µãÉÏ£¬²¢ÇÒÄ¿½ñ¸ÃÎó²îÒѾ·ºÆð±»Ê¹ÓÃÇéÐΡ£
Îó²îÏêÇ飺
WP SMTP²å¼þ 1.4.2¼°Ö®Ç°°æ±¾°üÀ¨Ò»ÏЧ£¬¿ÉΪվµã·¢Ë͵ÄËùÓеç×ÓÓʼþ£¨±êÍ·ºÍÕýÎÄ£©½¨Éèµ÷ÊÔÈÕÖ¾£¬È»ºó½«Æä´æ´¢ÔÚ×°ÖÃÎļþ¼ÐÖС£
Easy WP SMTP²å¼þʹÓõĵ÷ÊÔÈÕ־λÓÚ²å¼þµÄ×°ÖÃÎļþ¼Ð¡°/wp-content/plugins/easy-wp-smtp/¡±ÖУ¬¸ÃÈÕÖ¾ÊǰüÀ¨Ëæ»úÃû³ÆµÄÎı¾Îļþ£¨Èç5fcdb91308506_debug_log.txt£©¡£Easy WP SMTP²å¼þµÄÎļþ¼ÐûÓÐÈκÎindex.htmlÎļþ£¬Òò´ËÔÚÆôÓÃÁËĿ¼ÁбíµÄ·þÎñÆ÷ÉÏ£¬¹¥»÷Õß¿ÉÒÔ²éÕÒ²¢Éó²éÈÕÖ¾£º

È»ºó£¬¹¥»÷Õß¿ÉÒÔÖ´ÐÐͨÀýµÄÓû§Ãûö¾ÙɨÃ裬ÒÔ²éÕÒ¹ÜÀíÔ±µÇ¼Ãû£¬Èçͨ¹ýREST API£º

¹¥»÷ÕßÒ²¿ÉÒÔʹÓÃauthor achiveɨÃè(/?author=1)Ö´ÐÐÏàͬµÄʹÃü¡£
¹¥»÷ÕßʹÓôËÎó²îÔÚÈÕÖ¾Öбêʶ¹ÜÀíÔ±ÕÊ»§£¬²¢ÊµÑéÖØÖùÜÀíÔ±ÕÊ»§µÄÃÜÂ룺

ÃÜÂëÖØÖÃÀú³Ì½«´øÓÐÃÜÂëÖØÖÃÁ´½ÓµÄµç×ÓÓʼþ·¢Ë͵½adminÕÊ»§£¬²¢ÇҴ˵ç×ÓÓʼþ»á¼Í¼ÔÚEasy WP SMTPµÄµ÷ÊÔÈÕÖ¾ÖС£

¹¥»÷ÕßÔÚÖØÖÃÃÜÂëºó»á¼ûµ÷ÊÔÈÕÖ¾£¬»ñÈ¡ÖØÖÃÁ´½Ó£¬²¢¿ØÖƸÃÕ¾µãµÄ¹ÜÀíÔ±ÕÊ»§¡£

0x02 ´¦Öóͷ£½¨Òé
Easy WP SMTP²å¼þµÄ¿ª·¢Ö°Ô±Í¨¹ý½«²å¼þµÄµ÷ÊÔÈÕÖ¾ÒÆµ½WordPressÈÕÖ¾Îļþ¼ÐÖÐÀ´ÐÞ¸´ÁË´ËÎó²î£¬½¨ÒéÉý¼¶ÖÁ1.4.4°æ±¾¡£
ÏÂÔØÁ´½Ó£º
https://wordpress.org/plugins/easy-wp-smtp/#developers
0x03 ²Î¿¼Á´½Ó
https://wordpress.org/plugins/easy-wp-smtp/
https://blog.nintechnet.com/wordpress-easy-wp-smtp-plugin-fixed-zero-day-vulnerability/
https://securityaffairs.co/wordpress/112218/hacking/easy-wp-smtp-wordpress-plugin-flaw.html?
0x04 ʱ¼äÏß
2020-12-12 WordPress¸üÐÂÇ徲ͨ¸æ
2020-12-15 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ