天下漏洞,尽知其名
HIGH

CVE-2026-96326 HT Contact Form 存储型跨站脚本漏洞

影响未授权攻击者可注入恶意脚本,在用户访问页面时执行

AI 研判

WordPress 插件 HT Contact Form – Drag & Drop Form Builder 存在存储型跨站脚本漏洞。由于富文本编辑器字段的输入过滤与输出转义不足,攻击者可注入任意 Web 脚本。该漏洞影响所有 2.10.2 及之前版本,CVSS 评分为 7.2(HIGH)。

影响范围

HT Contact Form

HT Contact Form – Drag & Drop Form Builder for WordPress 插件,所有版本至 2.10.2(含)。

漏洞详情

漏洞类型为存储型跨站脚本(Stored XSS)。成因是插件对富文本编辑器字段的输入未充分过滤、输出未充分转义,导致恶意脚本被持久化存储。攻击者可通过表单提交将脚本注入页面,当其他用户访问被注入页面时脚本在浏览器中执行。

利用条件与风险

利用无需认证,攻击者可远程提交恶意内容;脚本在受害者浏览器中执行,可能导致会话劫持、敏感信息窃取或页面篡改,实战风险较高。

修复建议

建议升级至 2.10.2 之后的修复版本;若暂无可用更新,可暂时禁用富文本编辑器字段或限制表单提交权限作为缓解措施。

原始情报

The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Rich Text Editor Field in all versions up to, and including, 2.10.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.