CVE-2026-101923 WordPress Photo Reviews 插件任意内容删除漏洞
影响未授权攻击者可借管理员删除评论之机永久删除站点任意文章、页面、产品或媒体附件
Photo Reviews for WooCommerce 插件在 1.2.30 及之前版本中存在任意内容删除漏洞。插件在公开评论提交时未校验 wcpr_image_upload_id 参数对应的附件归属,将其直接存入评论元数据,删除评论时又无条件调用 wp_delete_post 删除这些 ID 对应的内容。攻击者无需认证即可提交恶意评论,待管理员删除该评论或系统定时清理回收站时触发删除。
影响范围
Photo Reviews for WooCommerce 插件 1.2.30 及更早版本受影响,暂无公开信息说明更高版本是否已修复。
漏洞详情
漏洞属于越权/任意内容删除类。成因是插件把用户可控的 wcpr_image_upload_id 参数值当作附件 ID 存入评论元数据,且未验证这些 ID 是否属于提交者,随后 delete_reviews_image() 处理函数在删除评论时对每个存储的 ID 直接执行 wp_delete_post( $id, true ),绕过权限与归属检查。攻击者只需提交带恶意 ID 的评论,即可在评论被删除时删除任意文章、页面、产品或媒体。
利用条件与风险
利用无需认证,但需诱导或等待管理员删除攻击者提交的评论,或等待 WordPress 内置 wp_scheduled_delete 定时任务在 30 天后清空评论回收站,实战中可造成站点内容被批量破坏。
修复建议
建议升级到官方已修复版本(暂无公开信息确认具体版本号),或暂时停用该插件;临时缓解可限制公开评论提交、及时审查并手动清理评论,避免触发删除逻辑。
The Photo Reviews for WooCommerce plugin for WordPress is vulnerable to Arbitrary Content Deletion in versions up to, and including, 1.2.30. This is due to the plugin storing attacker-controlled post IDs from the wcpr_image_upload_id parameter of a public review submission into the review’s reviews-images comment meta without verifying that the IDs correspond to attachments owned by the submitter, combined with the delete_reviews_image() handler unconditionally calling wp_delete_post( $id, true ) on every stored ID when the review is deleted. This makes it possible for unauthenticated attackers to permanently delete arbitrary posts, pages, products, or media attachments on the site whenever an administrator subsequently deletes the attacker’s review (or when WordPress’s built-in wp_scheduled_delete cron empties the comment trash after 30 days).