天下漏洞,尽知其名
MEDIUM

CVE-2026-93880 WordPress Greenshift 插件反射型 XSS 漏洞

影响攻击者可诱骗用户点击链接,在其浏览器中执行任意脚本

AI 研判

Greenshift 是 WordPress 的动画与页面构建区块插件。其动态占位符 {{GET:}} 在处理输入时缺乏充分的过滤与输出转义,导致反射型跨站脚本漏洞。攻击者可通过构造恶意链接,在受害者浏览器中注入并执行任意脚本。

影响范围

Greenshift

Greenshift 插件所有版本,直至并包含 13.2.0。

漏洞详情

漏洞类型为反射型跨站脚本(XSS),成因是插件对 {{GET:}} 动态占位符的输入未充分过滤、输出未转义。当站点管理员在元素区块的 Custom JS 字段中配置了 {{GET:...}} 占位符,且该 JS 包含 'import' 标记时,替换后的值会被路由到 <script type="module"> 标签内未转义的原始输出分支。攻击者借此注入恶意脚本,诱使用户点击链接后触发执行。

利用条件与风险

利用前提是管理员已配置包含 {{GET:...}} 且含 'import' 标记的 Custom JS 字段,攻击者无需认证即可通过诱骗用户点击链接实施攻击,实战风险中等。

修复建议

建议升级 Greenshift 插件至 13.2.0 之后的修复版本;临时缓解措施包括避免在 Custom JS 中使用 {{GET:}} 占位符,或对相关输入进行严格过滤与转义。

原始情报

The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ‘{{GET:}}’ Dynamic Placeholder in all versions up to, and including, 13.2.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. This requires a site administrator to have configured an element block’s Custom JS field to include a {{GET:…}} placeholder and for that JS to contain the token ‘import’, which routes the substituted value to the unescaped raw echo branch inside a <script type=”module”> tag.