CVE-2026-85573 All in One Files Upload 插件 SVG 上传漏洞
影响未认证攻击者可上传含活动内容的 SVG 文件,诱导受害者打开后执行恶意脚本
All in One Files Upload 是 WordPress 的文件上传插件,2.0.17 之前版本将 SVG 加入站点允许上传类型,且未对上传文件做净化处理,也未校验公开上传请求的真实性。未认证用户可借此上传包含活动内容(如脚本)的文件,当受害者打开时会在站点源下执行。
影响范围
All in One Files Upload WordPress 插件 2.0.17 之前的版本。
漏洞详情
漏洞类型为不受限文件上传/存储型 XSS。成因是插件把 SVG 加入允许上传类型,却未对 SVG 内容做净化,也未验证上传请求来源,导致未认证用户可直接上传含脚本的 SVG。受害者访问该文件时,脚本在站点同源下执行,可窃取会话或发起进一步攻击。
利用条件与风险
利用无需认证,攻击者只需能访问上传接口即可投递恶意 SVG,实战中可导致会话劫持或站点被进一步控制,风险较高。
修复建议
升级至 2.0.17 或更高版本;临时缓解可禁用 SVG 上传、限制上传接口访问并校验请求来源。
The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site’s allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site’s origin when a victim opens them.