CVE-2026-87091 WordPress Welcart 插件存储型 XSS 漏洞
影响未授权攻击者可注入恶意脚本,在管理员浏览日志时执行
Welcart e-Commerce 是 WordPress 的电商插件。其结算通知(IPN)接口未对 rel 和 option 参数做充分过滤与转义,导致存储型跨站脚本漏洞。攻击者提交的恶意载荷会被存入结算错误日志,并在管理员查看时执行。
影响范围
所有版本至 2.12.2(含)均受影响,暂无公开信息说明更高版本是否已修复。
漏洞详情
漏洞类型为存储型 XSS,成因是 IPN 端点接收 rel、option 参数时缺乏输入净化与输出转义,且无身份认证、nonce 校验或签名验证。未授权攻击者可直接向该接口提交恶意脚本,脚本被持久化存储后在管理员结算错误日志页面渲染执行。
利用条件与风险
利用无需认证,攻击者可直接远程提交载荷,但需诱导或等待管理员查看结算错误日志才能触发,实战中可用于窃取管理员会话或执行管理操作。
修复建议
建议升级至官方修复版本;若暂无补丁,可限制 IPN 端点访问、对 rel/option 参数进行严格过滤与输出转义,并避免管理员直接查看未净化的日志内容。
The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Settlement Notification Parameters in all versions up to, and including, 2.12.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The IPN endpoint accepts the ‘rel’ and ‘option’ parameters with no authentication, nonce validation, or signature verification, meaning any unauthenticated attacker can directly submit malicious payloads that are stored and later rendered in the administrator’s settlement error log view.