天下漏洞,尽知其名
MEDIUM

CVE-2026-103519 WordPress WP Ultimate Review 任意短代码执行漏洞

影响订阅者及以上权限用户可执行任意短代码,可能读取敏感数据或触发进一步攻击

AI 研判

WP Ultimate Review 是 WordPress 的评论/评分插件。该插件在所有 2.4.3 及之前版本中,因未对用户提交的值做充分校验便调用 do_shortcode,导致任意短代码执行。攻击者利用 WordPress 的 strip_shortcodes() 将 [[tag]] 双括号转义还原为 [tag],绕过过滤并在 xs_review 文章类型渲染时触发。

影响范围

WP Ultimate Review

WP Ultimate Review 插件所有版本至 2.4.3(含 2.4.3)。

漏洞详情

漏洞类型为任意短代码执行。成因是插件在处理用户可控输入时未正确校验便执行 do_shortcode。利用方式为:具有订阅者及以上权限的登录用户提交 [[tag]] 形式的双括号转义,WordPress 的 strip_shortcodes() 会将其还原为 [tag],该内容经 wp_insert_post 存储后,在公开可查询的 xs_review 文章类型通过 the_content 渲染时被当作短代码执行。

利用条件与风险

利用前提是攻击者拥有订阅者及以上权限的账号,且目标站点启用了该插件并存在可渲染的 xs_review 内容。实战中可借此执行任意短代码,可能泄露信息或配合其他插件造成更严重后果,CVSS 5.4 属中危。

修复建议

官方修复方案:升级至 2.4.3 之后的修复版本(暂无公开信息确认具体版本号)。临时缓解措施:限制订阅者等低权限用户发布内容,或禁用/卸载该插件,并对用户输入中的短代码进行严格过滤。

原始情报

The The WP Ultimate Review plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with subscriber-level access and above, to execute arbitrary shortcodes. The bypass relies on WordPress’s own strip_shortcodes() function unwrapping the [[tag]] double-bracket escape to a bare [tag] that survives wp_insert_post storage and fires when the publicly queryable xs_review post type is rendered through the_content.