天下漏洞,尽知其名
MEDIUM

CVE-2026-92712 ReactPress 存储型跨站脚本漏洞

影响具有订阅者及以上权限的攻击者可注入恶意脚本,在用户访问页面时执行

AI 研判

ReactPress 是 WordPress 的 Create React App 插件,其 permalink 参数未做充分的输入过滤与输出转义,导致存储型跨站脚本漏洞。攻击者可借此在页面中注入任意 Web 脚本,脚本会在其他用户访问被注入页面时执行。

影响范围

ReactPress

ReactPress 插件所有版本,包括 3.4.0 及之前版本。

漏洞详情

漏洞类型为存储型跨站脚本(Stored XSS)。成因是 permalink 参数仅经过 sanitize_url() 处理,该函数无法阻止获取攻击者控制的远程 URL,其响应体(含 script 标签和事件处理属性)会通过 file_put_contents() 原样写入磁盘。具有订阅者及以上权限的认证攻击者可注入恶意脚本,脚本在用户访问被注入页面时执行。

利用条件与风险

利用前提是攻击者拥有订阅者及以上权限的认证账户,且目标站点安装并启用了受影响版本的 ReactPress 插件。实战中可导致会话劫持、页面篡改等风险,CVSS 评分为 6.4(中危)。

修复建议

建议升级 ReactPress 插件至 3.4.0 之后的修复版本;在官方补丁发布前,可考虑停用该插件或限制低权限用户的访问。具体修复版本暂无公开信息。

原始情报

The ReactPress – Create React App for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘permalink’ parameter in all versions up to, and including, 3.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is possible because the permalink parameter is only passed through sanitize_url(), which does not prevent fetching attacker-controlled remote URLs whose response body — including script tags and event-handler attributes — is written verbatim to disk via file_put_contents().