天下漏洞,尽知其名
MEDIUM

CVE-2026-100180 Jeg Kit for Elementor 存储型XSS漏洞

影响攻击者可注入恶意脚本,在用户访问页面时执行

AI 研判

WordPress 插件 Jeg Kit for Elementor 在 3.2.19 及之前所有版本中存在存储型跨站脚本漏洞。由于输入清理和输出转义不足,攻击者可通过评论功能注入任意 Web 脚本。

影响范围

Jeg Kit for Elementor

影响 Jeg Kit for Elementor 插件所有版本至 3.2.19(含)。

漏洞详情

漏洞类型为存储型 XSS,成因是插件对评论输入缺乏充分的过滤与转义。未认证攻击者可在评论中注入恶意脚本,脚本被存储后会在其他用户访问该页面时自动执行。若攻击者使用已有获批评论记录的邮箱提交,还可绕过审核立即持久化。

利用条件与风险

利用无需认证,攻击者只需提交评论即可;若使用已获批评论的邮箱可绕过审核,实战风险较高,可能导致会话劫持或页面篡改。

修复建议

建议升级至官方修复版本;暂无公开信息说明具体修复版本,临时缓解可禁用评论功能或对评论内容进行严格过滤。

原始情报

The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, and including, 3.2.19 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Immediate persistence without moderator approval is possible when the attacker submits from an email address with at least one previously approved comment, though the widened allowlist bypasses sanitization regardless of approval status.