CVE-2026-92977 Real Cookie Banner 存储型 XSS 漏洞
影响未授权攻击者可注入恶意脚本,在用户访问页面时执行
WordPress 插件 Real Cookie Banner(GDPR 与 ePrivacy Cookie 同意插件)存在存储型跨站脚本漏洞。由于输入清理和输出转义不足,攻击者可通过评论注入任意 Web 脚本。该漏洞影响 5.3.5 及之前所有版本。
影响范围
Real Cookie Banner 插件 5.3.5 及之前所有版本(WordPress 环境)。
漏洞详情
漏洞类型为存储型跨站脚本(Stored XSS)。成因是插件对评论输入清理与输出转义不足:攻击者将恶意脚本放入 a 标签的 title 属性,保存时可绕过 WordPress 评论 kses 过滤,渲染时插件页面级正则移除闭合引号分隔符,使载荷变为可执行 HTML 属性。未授权攻击者可借此注入脚本,在用户访问被注入页面时执行。
利用条件与风险
利用前提是评论需经标准审核流程后才会公开展示,因此实际触发依赖评论被批准显示。一旦成功,可导致会话劫持、页面篡改等风险,CVSS 7.2 属高危。
修复建议
官方修复方案:升级至 5.3.5 之后的已修复版本(具体版本号暂无公开信息)。临时缓解:启用严格的评论审核与过滤,限制未授权评论展示,或暂时停用该插件。
The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, and including, 5.3.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Malicious script payloads placed in the title attribute of an anchor tag survive WordPress’s comment kses filter at save time, as the payload is only promoted to executable HTML attributes when the plugin’s page-wide regex strips the closing quote delimiter at render time; exploitability is therefore subject to the standard comment moderation workflow before the comment is publicly displayed.