CVE-2026-87777 Hostinger Reach WordPress 插件存储型 XSS 漏洞
影响贡献者及以上权限用户可注入脚本,在高权限用户会话中执行
Hostinger Reach 是 Hostinger 推出的 WordPress 插件。该插件在 1.8.3 之前的版本中,未对某个小工具(widget)设置进行清理和转义,便直接输出到编辑器预览中,从而形成存储型跨站脚本漏洞。
影响范围
Hostinger Reach WordPress 插件 1.8.3 之前的版本。
漏洞详情
漏洞类型为存储型 XSS(CWE-79)。成因是插件在将 widget 设置输出到编辑器预览时缺少输入清理与输出转义,恶意脚本被持久化保存。拥有 contributor 及以上权限的用户可注入任意 Web 脚本,当更高权限用户(如管理员)在编辑器中打开受影响内容时,脚本会在其浏览器会话中执行。
利用条件与风险
利用前提是攻击者拥有 contributor 或更高权限的账号,且高权限用户打开被污染的内容。实战中可用于会话劫持、权限提升或后台操作,CVSS 6.8 属中危。
修复建议
升级 Hostinger Reach 插件至 1.8.3 或更高版本。临时缓解措施包括限制低权限账号的创建、审查编辑器中的可疑内容,暂无其他公开信息。
The Hostinger Reach WordPress plugin before 1.8.3 does not sanitize and escape a widget setting before outputting it in the editor preview, allowing users with contributor-level access and above to inject arbitrary web scripts that will execute in the session of a higher-privileged user who opens the affected content in the editor.