CVE-2026-89294 WordPress Simply Schedule Appointments 本地文件包含漏洞
影响攻击者可包含并执行服务器上的任意 PHP 文件,导致敏感数据泄露或代码执行
Simply Schedule Appointments 是 WordPress 的一款预约插件。其 ssa_locale 参数存在本地文件包含漏洞,影响 1.6.12.27 及之前所有版本。攻击者可借此包含并执行服务器上的任意 .php 文件。
影响范围
Simply Schedule Appointments 插件所有版本至 1.6.12.27(含)。
漏洞详情
漏洞类型为本地文件包含(LFI),成因是插件对 ssa_locale 参数未做充分过滤即用于文件包含。该 locale 过滤器在 plugins_loaded 时无条件注册,回调未做 nonce 或权限校验便直接返回原始 GET 参数值,因此实际利用无需认证。攻击者可包含并执行服务器上的 .php 文件,从而绕过访问控制、获取敏感数据,若可上传 .php 文件还可实现代码执行。
利用条件与风险
利用前提是目标运行受影响版本插件,且服务器上存在可被包含的 .php 文件;由于过滤器无条件注册且无权限校验,实战中无需认证即可触发,风险较高。
修复建议
建议升级至 1.6.12.27 之后的修复版本;若暂无可用更新,可临时禁用该插件或通过 WAF 拦截针对 ssa_locale 参数的恶意请求。
The Simply Schedule Appointments plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.12.27 via the ‘ssa_locale’ parameter parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included. Notably, exploitation does not require authentication in practice, as the locale filter is installed unconditionally on every request during plugins_loaded and the callback performs no nonce or capability check before returning the raw GET parameter value.