CVE-2026-101357 SEOPress 存储型跨站脚本漏洞
影响低权限用户可注入恶意脚本,在管理员访问页面时执行
WordPress 插件 SEOPress 存在存储型跨站脚本漏洞,影响 10.2 及之前所有版本。漏洞源于对 seopress_google_analytics_matomo_id 参数输入过滤与输出转义不足,攻击者可注入任意 Web 脚本。
影响范围
SEOPress 插件所有版本至 10.2(含 10.2)。
漏洞详情
漏洞类型为存储型跨站脚本(Stored XSS)。由于插件未对 seopress_google_analytics_matomo_id 参数进行充分的输入清理和输出转义,拥有订阅者及以上权限的认证攻击者可将恶意脚本存入页面。当其他用户(如管理员)访问被注入的页面时,脚本会在其浏览器中执行。
利用条件与风险
利用前提是管理员已通过插件 Advanced > Security 设置将 Analytics 管理权限委派给订阅者角色。满足该条件时,低权限攻击者可持久化注入脚本,可能导致会话劫持或权限提升。
修复建议
官方已发布修复版本,建议升级至 10.2 之后的最新版本。临时缓解措施包括:撤销订阅者角色的 Analytics 管理权限,或停用相关功能。
The SEOPress – AI SEO Plugin & On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘seopress_google_analytics_matomo_id’ parameter in all versions up to, and including, 10.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires an administrator to have delegated the Analytics management capability to the Subscriber role via the plugin’s Advanced > Security settings.