CVE-2026-96647 Listdom WordPress 插件存储型 XSS 漏洞
影响攻击者可注入恶意脚本,在用户访问页面时执行
Listdom 是 WordPress 的 AI 商业目录与分类广告列表插件。其 lsd[remark] 参数因输入过滤与输出转义不足,存在存储型跨站脚本漏洞。攻击者可注入任意脚本,在用户访问被注入页面时执行。
影响范围
影响 Listdom 插件所有版本,包括 6.1.1 及之前版本。
漏洞详情
漏洞类型为存储型 XSS,成因是 lsd[remark] 参数未充分过滤输入且输出未转义。由于 AJAX 处理器的列表创建分支缺少权限检查,且所需 nonce 在含 [listdom-dashboard] 短代码的页面公开输出,订阅者级别用户即可利用。注入的脚本会持久化存储并在其他用户访问时执行。
利用条件与风险
利用前提是攻击者拥有订阅者及以上权限,并能访问含 [listdom-dashboard] 短代码的页面获取 nonce。实战中可窃取会话、劫持用户操作,风险中等。
修复建议
建议升级至官方修复版本;暂无公开信息时,可临时限制低权限用户创建列表、移除不必要的 [listdom-dashboard] 短代码或对 lsd[remark] 参数进行额外过滤。
The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ‘lsd[remark]’ Parameter in all versions up to, and including, 6.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable by Subscriber-level users because the listing-creation branch of the AJAX handler omits a capability check, and the required nonce is publicly emitted on any page containing the [listdom-dashboard] shortcode.