CVE-2026-93908 WordPress Real Estate Manager 存储型XSS漏洞
影响订阅者及以上权限用户可注入脚本,访问页面时执行
WordPress 的 Real Estate Manager – Property Listing and Agent Management 插件存在存储型跨站脚本漏洞。由于对 before_price_text 参数输入过滤与输出转义不足,且 wp_ajax_rem_create_pro_ajax 处理函数缺少权限、nonce 与归属校验,攻击者可持久化注入恶意脚本。
影响范围
影响该插件所有版本,包括 7.3 及之前版本。
漏洞详情
漏洞类型为存储型 XSS,成因是 before_price_text 参数未做充分过滤与转义,且 AJAX 处理函数缺少权限、nonce 和归属检查。由于数据通过 update_post_meta 持久化而非 post_content,与 unfiltered_html 能力关联的 wp_kses 过滤不会生效。具有订阅者及以上权限的认证用户可注入任意 Web 脚本,在用户访问被注入页面时执行。
利用条件与风险
利用前提是攻击者拥有订阅者及以上权限的账户;实战中可窃取会话、篡改页面或进行钓鱼,风险中等。
修复建议
建议升级到官方修复版本;暂无公开信息时,可临时限制低权限用户访问相关 AJAX 接口或对 before_price_text 参数进行过滤与转义。
The Real Estate Manager – Property Listing and Agent Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘before_price_text’ parameter in all versions up to, and including, 7.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability is further enabled by the absence of any capability, nonce, or ownership check on the wp_ajax_rem_create_pro_ajax handler, and because the value is persisted via update_post_meta rather than post_content, the wp_kses filtering tied to the unfiltered_html capability does not apply.