CVE-2026-85415 Audio Player Block 存储型XSS漏洞
影响攻击者可注入恶意脚本并在其他用户会话中执行
WordPress 插件 Audio Player Block 1.6.3 之前版本在使用用户提供的 URL 作为链接目标前未校验其 scheme,导致存储型跨站脚本漏洞。具有 Contributor 及以上角色的用户可存储恶意 JavaScript,当管理员或编辑等用户触发该链接时脚本在其会话中执行。
影响范围
漏洞详情
漏洞类型为存储型 XSS,成因是插件未对用户提交 URL 的协议方案(scheme)进行校验,允许 javascript: 等危险协议被保存为链接目标。攻击者以 Contributor 及以上权限在文章内容中植入恶意链接,受害者点击后脚本在浏览器中执行。
利用条件与风险
利用需攻击者拥有 Contributor 及以上角色权限,且需诱导管理员或编辑点击恶意链接;成功利用可窃取会话、执行管理操作,实战风险中等。
修复建议
升级 Audio Player Block 至 1.6.3 或更高版本;暂无公开信息说明其他临时缓解措施,建议限制低权限用户的内容发布权限并谨慎点击不可信链接。
The Audio Player Block WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as a link target, allowing users with the Contributor role and above to store malicious JavaScript that executes in the session of any user who later triggers the link (such as an administrator or editor reviewing the post).