天下漏洞,尽知其名
MEDIUM

CVE-2025-12828 Ultra Addons Lite for Elementor 存储型跨站脚本漏洞

影响具有贡献者及以上权限的攻击者可注入恶意脚本,在用户访问页面时执行

AI 研判

WordPress 插件 Ultra Addons Lite for Elementor 的 Type Out 小部件存在存储型跨站脚本漏洞。由于对用户提供的属性输入过滤和输出转义不足,攻击者可注入任意 Web 脚本。该漏洞影响 1.3.2 及之前的所有版本。

影响范围

Ultra Addons Lite for Elementor

Ultra Addons Lite for Elementor 插件 1.3.2 及之前的所有版本。

漏洞详情

漏洞类型为存储型跨站脚本(Stored XSS),成因是 Type Out 小部件对用户可控属性缺乏充分的输入清理与输出转义。具有贡献者(Contributor)及以上权限的已认证攻击者可将恶意脚本存入页面,当其他用户访问该页面时脚本在浏览器中执行。

利用条件与风险

利用需攻击者拥有贡献者及以上权限的账户,属于已认证攻击。实战中可导致会话劫持、页面篡改或钓鱼等风险,CVSS 评分 6.4 为中危。

修复建议

建议升级至官方修复版本(暂无公开信息说明具体修复版本号);临时缓解措施包括限制贡献者权限、禁用或移除 Type Out 小部件,或对用户输入进行额外过滤。

原始情报

The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Type Out widget in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.