CVE-2026-92551 ProfilePress 反射型跨站脚本漏洞
影响未认证攻击者可注入并执行任意脚本,窃取用户会话等
WordPress 插件 ProfilePress(付费会员、电商、用户注册/登录表单、用户资料与内容限制插件)存在反射型跨站脚本漏洞。由于对 ppress_billing_address 文件上传字段的 Filename 参数输入过滤与输出转义不足,攻击者可构造恶意请求注入脚本。该漏洞影响所有 4.17.4 及之前版本。
影响范围
漏洞详情
漏洞类型为反射型 XSS,成因是插件未对 ppress_billing_address 文件上传字段的文件名参数进行充分的输入清理和输出转义。攻击者可通过构造恶意 POST 请求,在托管 ProfilePress Tabbed Widget 的任意页面上注入任意 Web 脚本。当用户被诱骗点击链接或执行操作时,注入的脚本会在其浏览器中执行。
利用条件与风险
利用无需认证,但需诱导用户访问恶意构造的页面或点击链接,属于典型反射型 XSS 场景。实战中可用于会话劫持、钓鱼或页面篡改,CVSS 6.1 为中危。
修复建议
官方已发布修复版本,建议升级至 4.17.4 之后的版本;若暂无升级条件,可暂时禁用或移除 ProfilePress Tabbed Widget,并对上传字段文件名参数进行严格过滤与转义。
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter in all versions up to, and including, 4.17.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The vulnerability is exploitable via any page hosting the ProfilePress Tabbed Widget by supplying a malicious filename for the ppress_billing_address file upload field in a crafted POST request.