CVE-2026-92727 EmbedPress 存储型跨站脚本漏洞
影响具有贡献者权限的攻击者可注入恶意脚本,在用户访问页面时执行
EmbedPress 是 WordPress 的一款用于嵌入 PDF、Google 评论、YouTube 视频等内容的插件。该插件在处理 slidesShow 区块属性时输入过滤与输出转义不足,导致存储型跨站脚本漏洞。攻击者可注入任意 Web 脚本,在用户访问被注入页面时执行。
影响范围
EmbedPress 所有版本,包括 4.6.6 及之前版本。
漏洞详情
漏洞类型为存储型跨站脚本(Stored XSS),成因是 slidesShow 区块属性被插入到未加引号的 data-carousel-options HTML 属性中,且缺乏充分的输入过滤和输出转义。攻击者可构造包含空格的载荷突破该属性,向包装元素注入额外的 DOM 属性,例如 onfocus 事件处理器。当用户访问被注入的页面时,恶意脚本即被执行。
利用条件与风险
利用前提是攻击者拥有贡献者及以上权限的账户,可创建或编辑包含恶意区块的内容。实战中可导致会话劫持、页面篡改或钓鱼等风险,但需要用户交互触发。
修复建议
官方已发布修复版本,建议升级至 4.6.6 之后的版本。临时缓解措施包括限制贡献者及以上权限账户的创建、审查用户提交内容,或暂时禁用相关区块功能。具体修复版本请以官方公告为准。
The EmbedPress – PDF Embedder, 3D PDF FlipBook, Google Reviews, YouTube Videos, Upload & Embed PDF documents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ‘slidesShow’ Block Attribute in all versions up to, and including, 4.6.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The slidesShow block attribute is interpolated into an unquoted data-carousel-options HTML attribute, allowing a payload containing spaces to break out of the attribute and inject additional DOM attributes such as onfocus event handlers onto the wrapper element.