天下漏洞,尽知其名
MEDIUM

CVE-2026-88037 WordPress Bold Page Builder 存储型 XSS 漏洞

影响攻击者可注入恶意脚本,在用户访问页面时执行

AI 研判

Bold Page Builder 是 WordPress 的一款页面构建插件。其 bt_bb_service 短代码的 title 属性存在输入过滤与输出转义不足的问题,导致存储型跨站脚本漏洞。攻击者可注入任意脚本,在用户访问被注入页面时执行。

影响范围

Bold Page Builder

影响 Bold Page Builder 插件所有版本,包括 5.7.2 及之前版本。

漏洞详情

漏洞类型为存储型跨站脚本(XSS),成因是插件对 bt_bb_service 短代码 title 属性未进行充分的输入清理和输出转义。具有 Contributor 及以上权限的已认证攻击者可将恶意脚本注入页面内容中,脚本被持久化存储,任何用户访问该页面时即触发执行。

利用条件与风险

利用需攻击者拥有 Contributor 或更高权限的账户,可持久化注入脚本,实战中可用于会话劫持、钓鱼或权限提升等。

修复建议

建议关注厂商发布的修复版本并及时升级插件;临时缓解可限制低权限用户的内容发布权限或对短代码属性进行额外过滤。

原始情报

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `title` attribute of the `bt_bb_service` shortcode in all versions up to, and including, 5.7.2. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.