CVE-2026-6173 WordPress Bold Page Builder 存储型 XSS 漏洞
影响攻击者可注入恶意脚本,在用户访问页面时执行
WordPress 的 Bold Page Builder 插件在 bt_bb_section 短代码的 background_image 参数上存在输入过滤与输出转义不足的问题,导致存储型跨站脚本漏洞。攻击者可借此在页面中注入任意 Web 脚本,脚本会在其他用户访问该页面时执行。
影响范围
影响 Bold Page Builder 插件所有版本,包括 5.7.2 及之前版本。
漏洞详情
漏洞类型为存储型跨站脚本(Stored XSS),成因是插件对用户可控的 background_image 属性未做充分的输入清理和输出转义。具有 Contributor 及以上权限的已认证用户可提交包含恶意脚本的内容,脚本被持久化存储后,在任意用户浏览被注入页面时于其浏览器中执行。
利用条件与风险
利用需攻击者拥有 Contributor 或更高权限的账户,属于低权限认证用户可触发的持久化 XSS,可导致会话劫持、页面篡改等风险,CVSS 评分 6.4。
修复建议
建议升级至官方修复版本;若暂无可用更新,可限制 Contributor 及以上权限用户的不可信内容提交,或对 bt_bb_section 短代码的 background_image 参数进行额外过滤与转义。具体修复版本暂无公开信息。
The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘background_image’ parameter of the plugin’s bt_bb_section shortcode in all versions up to, and including, 5.7.2 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.