天下漏洞,尽知其名
HIGH

CVE-2026-96575 WordPress Transliterator 插件存储型 XSS 漏洞

影响未授权攻击者可注入恶意脚本,在用户访问页面时执行

AI 研判

WordPress 的 Transliterator – Multilingual and Multi-script Text Conversion 插件存在存储型跨站脚本漏洞。由于输入过滤和输出转义不足,攻击者可通过评论内容注入任意 Web 脚本。该漏洞影响所有 2.5.8 及之前版本。

影响范围

WordPress Transliterator 插件

Transliterator 插件所有版本至 2.5.8(含 2.5.8)。

漏洞详情

漏洞类型为存储型 XSS,成因是插件对评论内容中可预测的 {rstr_keep} 占位符处理不当,未充分过滤和转义。攻击者可利用 a[title]、code 等被 WordPress 评论 kses 白名单允许的标签和属性构造恶意载荷,且插件的短代码标记和占位符字面字符未被剥离,导致载荷在评论保存时存活。最终脚本会在用户访问被注入页面时执行。

利用条件与风险

利用无需认证,攻击者只需提交包含恶意载荷的评论即可。实战中可导致会话劫持、页面篡改或恶意重定向等风险。

修复建议

官方已发布修复版本,建议升级至 2.5.8 之后的最新版本。临时缓解措施包括禁用评论功能或对评论内容进行额外过滤,暂无其他公开信息。

原始情报

The Transliterator – Multilingual and Multi-script Text Conversion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content via Predictable {rstr_keep} Placeholder in all versions up to, and including, 2.5.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload survives WordPress comment save-time sanitization because the tags and attributes used (such as a[title] and code) are permitted by the core comment kses allow-list, and the literal characters comprising the plugin’s shortcode markers and placeholder tokens are not stripped.