天下漏洞,尽知其名
HIGH

CVE-2026-101928 WordPress Magic Tooltips For Contact Form 7 存储型 XSS 漏洞

影响未授权攻击者可注入恶意脚本,管理员访问评论页时执行

AI 研判

WordPress 插件 Magic Tooltips For Contact Form 7 存在存储型跨站脚本漏洞。由于输入过滤与输出转义不足,未认证攻击者可通过评论 author 参数注入任意 Web 脚本。该脚本会在用户访问被注入页面时执行。

影响范围

Magic Tooltips For Contact Form 7

影响该插件所有版本,包括 1.0.34 及之前版本。

漏洞详情

漏洞类型为存储型 XSS,成因是插件对输入过滤和输出转义不足。其 esc_html 过滤回调会将 HTML 实体编码的载荷(如包含 <tip> 的内容)解码回活动 HTML,从而绕过 sanitize_text_field。攻击者以评论作者名提交实体编码的脚本载荷,当管理员查看 wp-admin/edit-comments.php 时即被渲染为可执行标记。

利用条件与风险

利用无需认证,攻击者只需提交恶意评论作者名即可。实战中可劫持管理员会话或执行任意操作,风险较高。

修复建议

建议升级到修复该漏洞的插件版本;暂无公开信息时,可临时禁用评论作者名显示或对输出进行严格转义。

原始情报

The Magic Tooltips For Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author’ parameter in all versions up to, and including, 1.0.34 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because the plugin’s esc_html filter callback decodes HTML-entity-encoded payloads (e.g. those containing ‘<tip>’) back into live HTML, meaning an entity-encoded script payload submitted as a comment author name — which bypasses sanitize_text_field — is rendered as executable markup when an administrator views wp-admin/edit-comments.php.