CVE-2026-100148 WordPress Rich Showcase for Google Reviews 存储型XSS漏洞
影响攻击者可注入恶意脚本,在访客浏览页面时执行
WordPress 插件 Rich Showcase for Google Reviews 存在存储型跨站脚本漏洞,影响 7.1.3 及之前所有版本。漏洞源于对 reviews[].text 参数输入过滤和输出转义不足,恶意脚本可被持久化存储并在页面访问时执行。
影响范围
Rich Showcase for Google Reviews 插件所有版本至 7.1.3(含)。
漏洞详情
该漏洞属于存储型 XSS,成因是插件未对 Google 评论中的 reviews[].text 字段进行充分的输入净化和输出转义。攻击者可通过在关联商家下发布含恶意脚本的 Google 评论,插件默认每日定时任务会自动导入该评论内容,脚本在访客页面 DOMContentLoaded 时自动执行,无需额外交互。
利用条件与风险
利用前提是目标站点已连接 Google 商家评论并启用自动导入功能,攻击者无需 WordPress 账户即可通过发布恶意评论触发;实战中可导致访客会话劫持、页面篡改等风险。
修复建议
建议升级至官方修复版本;若暂无补丁,可临时禁用评论自动导入功能或对导入内容进行额外过滤转义。具体修复版本暂无公开信息。
The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘reviews[].text’ parameter in all versions up to, and including, 7.1.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is delivered entirely through a Google review posted for the connected business and requires no WordPress account; the plugin’s default daily cron auto-imports the malicious review text, and execution triggers for every visitor on DOMContentLoaded without any further user interaction.