天下漏洞,尽知其名
HIGH

CVE-2026-93889 WordPress WP Mail Catcher 存储型 XSS 漏洞

影响未认证攻击者可注入恶意脚本,在用户访问页面时执行

AI 研判

WordPress 插件 Mail logging – WP Mail Catcher 存在存储型跨站脚本漏洞。由于对 PHPMailer 的 wp_mail_failed 错误消息输入过滤和输出转义不足,攻击者可注入任意 Web 脚本。该脚本会在用户访问被注入页面时执行。

影响范围

WP Mail Catcher

影响 WP Mail Catcher 所有版本,包括 2.1.12 及之前版本。

漏洞详情

漏洞类型为存储型跨站脚本(XSS),成因是插件未对 PHPMailer 失败错误消息中的用户可控输入进行充分过滤与转义。攻击者需借助其他插件(如 Contact Form 7)将未认证用户输入传入邮件字段,PHPMailer 在失败错误消息中包含该内容,从而注入恶意脚本。脚本被存储后,任何访问相关页面的用户都会触发执行。

利用条件与风险

利用前提是站点安装了可传递未认证用户输入至邮件字段的插件(如 Contact Form 7)。实战中可导致会话劫持、页面篡改或恶意重定向等风险。

修复建议

建议更新至官方修复版本;若暂无更新,可禁用相关邮件日志功能或限制未认证输入进入邮件字段,并部署 Web 应用防火墙规则过滤恶意脚本。

原始情报

The Mail logging – WP Mail Catcher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PHPMailer ‘wp_mail_failed’ Error Message in all versions up to, and including, 2.1.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Successful exploitation requires a separately installed plugin, such as Contact Form 7, that passes unauthenticated user-controlled input into mail fields whose content PHPMailer will include in its failure error message.