天下漏洞,尽知其名
MEDIUM

CVE-2026-100157 WordPress WP Ultimate Review 任意短代码执行漏洞

影响未授权攻击者可执行任意短代码,可能导致信息泄露或进一步利用

AI 研判

WordPress 插件 WP Ultimate Review 在 2.4.3 及之前版本中存在任意短代码执行漏洞。插件在执行 do_shortcode 前未正确校验传入值,且所需 nonce 通过公开评论表单泄露给未认证访客,提交的短代码载荷默认自动发布、无需管理员审核。

影响范围

WP Ultimate Review

受影响范围为 WP Ultimate Review 插件所有版本至 2.4.3(含)。

漏洞详情

漏洞类型为任意短代码执行。成因是插件在处理用户提交内容时未对值进行充分校验便调用 do_shortcode,导致攻击者可注入并执行任意已注册短代码。利用方式为:未认证攻击者从公开评论表单获取 nonce,提交含短代码的载荷,因默认自动发布而无需管理员审批即可触发执行。

利用条件与风险

利用无需账号和特权交互,仅需获取公开表单中的 nonce,实战中可被未认证攻击者远程触发,风险中等。

修复建议

建议升级 WP Ultimate Review 插件至 2.4.3 之后的修复版本;若暂无可用更新,可考虑停用该插件或限制评论表单的公开提交与自动发布功能作为临时缓解。

原始情报

The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. The nonce required to pass the only gate is emitted to unauthenticated visitors via the public review form, and submitted shortcode payloads are auto-published without admin approval by default, meaning exploitation requires no account and no privileged interaction.