天下漏洞,尽知其名
MEDIUM

CVE-2026-85001 EmbedPress 存储型XSS漏洞

影响具有 Contributor 及以上权限的用户可注入脚本,在他人浏览页面时执行

AI 研判

EmbedPress 是 WordPress 的一款内容嵌入插件。其 4.6.7 之前版本在处理某个 Elementor 小部件设置时,未对输出到 HTML 属性的内容进行清理和转义,导致存储型跨站脚本漏洞。攻击者可将恶意脚本持久化存储,在受影响内容被查看时触发执行。

影响范围

EmbedPress

漏洞详情

漏洞类型为存储型跨站脚本(Stored XSS)。成因是插件在将 Elementor 小部件的某项设置输出到 HTML 属性前,缺少必要的过滤与转义处理。拥有 Contributor 或更高角色的用户可借此注入任意 Web 脚本,脚本随内容保存并在其他用户访问时执行。

利用条件与风险

利用前提是攻击者需具备 Contributor 或更高角色权限,属于需要一定权限的存储型 XSS。实战中可用于会话劫持、页面篡改或配合其他攻击扩大影响,CVSS 评分 6.8,风险等级为中危。

修复建议

官方已在 4.6.7 版本中修复,建议升级至 4.6.7 或更高版本。临时缓解措施包括限制 Contributor 及以上角色的授予、审查并清理已存储的恶意内容,暂无其他公开信息。

原始情报

The EmbedPress WordPress plugin before 4.6.7 does not sanitise and escape one of its Elementor widget settings before outputting it into an HTML attribute, which could allow users with the Contributor role or above to inject arbitrary web scripts that execute when the affected content is viewed.