天下漏洞,尽知其名
HIGH

CVE-2026-96564 WordPress SEOPress 存储型跨站脚本漏洞

影响攻击者可注入恶意脚本,在用户访问页面时执行

AI 研判

SEOPress 是 WordPress 的 AI SEO 与站内 SEO 插件。其 10.2 及之前所有版本因输入过滤与输出转义不足,存在存储型跨站脚本漏洞,攻击者可通过作者显示名称注入恶意脚本。

影响范围

SEOPress

SEOPress 插件所有版本至 10.2(含 10.2)。

漏洞详情

漏洞类型为存储型 XSS,成因是插件对作者显示名称的输入未充分过滤、输出未转义。当插件在 Google Analytics 4 或 Matomo 设置中启用了 'Track Authors' 自定义维度时,注入的显示名称会被渲染进跟踪脚本。攻击者需能发布公开的单篇内容(如通过 bbPress 论坛主题)以触发渲染。

利用条件与风险

利用前提是启用了 'Track Authors' 自定义维度且攻击者可发布公开内容;成功利用后可在受害者浏览器中执行任意脚本,可能导致会话劫持或页面篡改。

修复建议

建议升级至修复该漏洞的 SEOPress 版本(暂无公开信息);临时缓解可禁用 'Track Authors' 自定义维度或限制低权限用户发布公开内容。

原始情报

The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Author Display Name in all versions up to, and including, 10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the ‘Track Authors’ custom dimension to be configured in the plugin’s Google Analytics 4 or Matomo settings, and the attacker must be able to publish public singular content (e.g., via bbPress forum topics) so that the injected display name is rendered in the tracking script.