天下漏洞,尽知其名
MEDIUM

CVE-2026-97338 WordPress Download Manager 存储型XSS漏洞

影响攻击者可注入恶意脚本,在用户访问页面时执行

AI 研判

WordPress Download Manager 插件在所有 3.3.70 及之前版本中存在存储型跨站脚本漏洞。由于输入清理和输出转义不足,具有订阅者及以上权限的认证攻击者可通过显示名称字段注入任意 Web 脚本。

影响范围

WordPress Download Manager

Download Manager 插件所有版本至 3.3.70(含)。

漏洞详情

漏洞类型为存储型 XSS,成因是显示名称字段的输入清理与输出转义不充分。攻击者需利用前端页面上的 [wpdm_edit_profile] 短代码,通过提交多重实体编码的载荷绕过清理,将恶意脚本持久化存储。当其他用户访问被注入的页面时,脚本将在其浏览器中执行。

利用条件与风险

利用前提是前端页面存在 [wpdm_edit_profile] 短代码且允许订阅者级别用户访问。攻击者可借此窃取会话、篡改页面或进行钓鱼,实战风险中等。

修复建议

官方已发布修复版本,建议升级至 3.3.70 之后的版本。临时缓解措施包括移除或限制 [wpdm_edit_profile] 短代码的访问权限,并对用户输入进行严格过滤。

原始情报

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Display Name in all versions up to, and including, 3.3.70 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the [wpdm_edit_profile] shortcode to be present on a front-end page accessible to Subscriber-level users, who can then submit a multiply entity-encoded payload via the display name field to bypass sanitization.