天下漏洞,尽知其名
HIGH

CVE-2026-87741 ConvertPlus 插件反序列化漏洞

影响低权限用户可注入 PHP 对象,配合 POP 链可致远程代码执行

AI 研判

ConvertPlus 是 WordPress 的一款弹窗/转化组件插件。其 cp_display_preview_modal AJAX 接口存在不可信数据反序列化漏洞,影响 3.6.3 及之前所有版本。攻击者可借助 style 参数注入短代码,最终将可控数据传入 maybe_unserialize()。

影响范围

ConvertPlus WordPress 插件

ConvertPlus 插件所有版本至 3.6.3(含)。暂无公开信息说明更高版本是否已修复。

漏洞详情

漏洞源于 nonce 校验被 isset() 包裹,省略 cp_admin_page_nonce 参数时校验直接失效,且回调未做权限检查。style 参数经 sanitize_text_field() 处理后未过滤短代码定界符,被拼接进 do_shortcode() 执行,攻击者可注入第二个 [smile_modal] 短代码。该短代码将攻击者提供的 base64 数据交给 maybe_unserialize() 且未限制 allowed_classes,从而实现 PHP 对象注入。

利用条件与风险

利用需具备 Subscriber 及以上已认证账号,且站点需额外安装含 POP 链的插件或主题,否则无实际影响;一旦存在可用 POP 链,可升级为远程代码执行。

修复建议

建议升级至官方修复版本(暂无公开信息确认具体版本号),或临时禁用/限制 cp_display_preview_modal 接口访问并移除不必要的含 POP 链插件。

原始情报

The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 3.6.3 via the style parameter of the cp_display_preview_modal AJAX action. The vulnerability exists because the action’s nonce guard is gated behind an isset() check and fails open when the cp_admin_page_nonce parameter is omitted entirely, no capability check is performed on the callback, and sanitize_text_field() — applied to the $style value before it is concatenated directly into a shortcode string evaluated by do_shortcode() — does not strip shortcode delimiters, allowing an attacker to inject a second, fully attacker-controlled [smile_modal] invocation that causes smile_modal_popup() to pass attacker-supplied base64-decoded bytes to maybe_unserialize() with no allowed_classes restriction. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject a PHP object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme containing a POP chain is installed on the site. If a POP chain is present via an additional plugin or theme installed on the target system, it may allow the attacker to perform actions like delete arbitrary files, retrieve sensitive data, or execute code depending on the POP chain present.