¡¾·ì϶¹«¸æ¡¿WordPress Easy WP SMTP²å¼þ0 day·ì϶
°ä²¼¹¦·ò 2020-12-150x00 ·ì϶¸ÅÊö
CVE ID | ÔÝÎÞ | ʱ ¼ä | 2020-12-15 |
Àà ÐÍ | Éè¼ÆÃýÎó | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ÊÇ | Ó°ÏìÁìÓò | 1.4.2¼°Ö®Ç°°æ±¾ |
0x01 ·ì϶ÏêÇé

WordPressÊÇʹÓÃPHP¿ª·¢µÄ²©¿Íƽ̨£¬Óû§Äܹ»ÔÚÖ§³ÖPHPºÍMySQLÊý¾Ý¿âµÄ·þÎñÆ÷ÉϼÜÉèÊôÓÚ×Ô¼ºµÄÍøÕ¾£¬Ò²Äܹ»°Ñ WordPressµ±×÷Ò»¸öÄÚÈÝÖÎÀíϵͳ£¨CMS£©À´Ê¹Óá£WordPress Easy WP SMTPÊÇÒ»¸ö¼òÒ×µÄWP SMTP²å¼þ£¬×°ÖúóÄܹ»ÅäÖò¢Í¨¹ýSMTP·þÎñÆ÷·¢Ë͵ç×ÓÓʼþ¡£
½üÈÕ£¬WordPress ½¨¸´ÁËEasy WP SMTP²å¼þÖеÄÒ»¸ö0day·ì϶£¬¹¥»÷ÕßÄܹ»ÀûÓø÷ì϶³ÁÖÃÖÎÀíÔ±ÃÜÂë¡¢ÔÚ²©¿ÍÉÏ×°ÖÃµØÆ¦²å¼þµÈ¡£Ä¿Ç°£¬¸Ã²å¼þ±»×°ÖÃÔÚ500,000¶à¸öÕ¾µãÉÏ£¬²¢ÇÒµ±Ç°¸Ã·ì϶ÒѾ³öÏÖ±»ÀûÓÃÇé¿ö¡£
·ì϶ÏêÇ飺
WP SMTP²å¼þ 1.4.2¼°Ö®Ç°°æ±¾Ô̺¬Ò»ÏîÖ°ÄÜ£¬¿ÉΪվµã·¢Ë͵ÄËùÓеç×ÓÓʼþ£¨±êÍ·ºÍÕýÎÄ£©´´½¨µ÷ÊÔÈÕÖ¾£¬¶øºó½«Æä´æ´¢ÔÚ×°ÖÃÎļþ¼ÐÖС£
Easy WP SMTP²å¼þʹÓõĵ÷ÊÔÈÕ־λÓÚ²å¼þµÄ×°ÖÃÎļþ¼Ó×°/wp-content/plugins/easy-wp-smtp/¡±ÖУ¬¸ÃÈÕÖ¾ÊÇÔ̺¬Ëæ»úÃû³ÆµÄÎı¾Îļþ£¨Èç5fcdb91308506_debug_log.txt£©¡£Easy WP SMTP²å¼þµÄÎļþ¼ÐûÓÐÈκÎindex.htmlÎļþ£¬Òò¶øÔÚÆôÓÃÁËĿ¼ÁбíµÄ·þÎñÆ÷ÉÏ£¬¹¥»÷ÕßÄܹ»²éÕÒ²¢²é¿´ÈÕÖ¾£º

¶øºó£¬¹¥»÷ÕßÄܹ»Ö´ÐÐͨÀýµÄÓû§Ãûö¾ÙɨÃ裬ÒÔ²éÕÒÖÎÀíÔ±µÇ¼Ãû£¬Èçͨ¹ýREST API£º

¹¥»÷ÕßÒ²Äܹ»Ê¹ÓÃauthor achiveɨÃè(/?author=1)Ö´ÐÐÒ»ÑùµÄ¹¤×÷¡£
¹¥»÷ÕßÀûÓô˷ì϶ÔÚÈÕÖ¾ÖбêʶÖÎÀíÔ¹ØÊ»§£¬²¢³¢ÊÔ³ÁÖÃÖÎÀíÔ¹ØÊ»§µÄÃÜÂ룺

ÃÜÂë³ÁÖùý³Ì½«´øÓÐÃÜÂë³ÁÖÃÁ´½ÓµÄµç×ÓÓʼþ·¢Ë͵½adminÕÊ»§£¬²¢ÇҴ˵ç×ÓÓʼþ»á¼Í¼ÔÚEasy WP SMTPµÄµ÷ÊÔÈÕÖ¾ÖС£

¹¥»÷ÕßÔÚ³ÁÖÃÃÜÂëºó½Ó¼ûµ÷ÊÔÈÕÖ¾£¬»ñÈ¡³ÁÖÃÁ´½Ó£¬²¢½ÚÔì¸ÃÕ¾µãµÄÖÎÀíÔ¹ØÊ»§¡£

0x02 ´ëÖý¨Òé
Easy WP SMTP²å¼þµÄ¿ª·¢ÈËԱͨ¹ý½«²å¼þµÄµ÷ÊÔÈÕÖ¾ÒÆµ½WordPressÈÕÖ¾Îļþ¼ÐÖÐÀ´½¨¸´ÁË´Ë·ì϶£¬½¨ÒéÉý¼¶ÖÁ1.4.4°æ±¾¡£
ÏÂÔØÁ´½Ó£º
https://wordpress.org/plugins/easy-wp-smtp/#developers
0x03 ²Î¿¼Á´½Ó
https://wordpress.org/plugins/easy-wp-smtp/
https://blog.nintechnet.com/wordpress-easy-wp-smtp-plugin-fixed-zero-day-vulnerability/
https://securityaffairs.co/wordpress/112218/hacking/easy-wp-smtp-wordpress-plugin-flaw.html?
0x04 ¹¦·òÏß
2020-12-12 WordPress¸üа²È«²¼¸æ
2020-12-15 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ