CVE-2026-96270 Ultimate Member 存储型 XSS 漏洞
影响未授权攻击者可注入恶意脚本,管理员查看用户记录时触发执行
WordPress 插件 Ultimate Member 在 2.13.1 及之前版本中存在存储型跨站脚本漏洞。由于对 'form_id' 参数输入过滤和输出转义不足,未授权攻击者可在注册时注入任意 Web 脚本。注入的载荷存储在注册用户的 'submitted' usermeta 中,当管理员在 wp-admin 用户模态框中打开该用户记录时,通过 jQuery .html() 插入未转义输出从而触发执行。
影响范围
Ultimate Member 插件所有版本至 2.13.1(含 2.13.1)。
漏洞详情
漏洞类型为存储型跨站脚本(Stored XSS)。成因是插件对 'form_id' 参数缺乏充分的输入清理和输出转义,攻击者可在注册表单提交时注入恶意脚本。注入内容通过 update_user_meta() 持久化存储于用户的 'submitted' 元数据中,仅在管理员于后台用户管理模态框查看该用户时,由 jQuery .html() 方法将未转义数据插入 DOM 而触发。
利用条件与风险
利用无需认证,攻击者仅需提交注册表单即可注入载荷;但触发需管理员在后台打开受影响用户记录,实战中可导致管理员会话劫持或后台任意操作。
修复建议
官方已发布修复版本,建议升级至 2.13.1 之后的最新版本。临时缓解措施包括:对 'form_id' 参数进行严格白名单校验、在输出到管理界面时进行 HTML 转义,或暂时禁用用户注册功能。
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘form_id’ parameter in all versions up to, and including, 2.13.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The injected payload is stored in the registering user’s ‘submitted’ usermeta via update_user_meta() and is only triggered when an administrator opens the affected user record in the wp-admin Users modal, which inserts the unescaped output via jQuery .html().