CVE-2026-97344 WordPress Wp Social Login 插件存储型XSS漏洞
影响攻击者可注入恶意脚本,在用户访问页面时执行
WordPress 的 Wp Social Login and Register Social Counter 插件在 3.2.1 及之前所有版本中存在存储型跨站脚本漏洞。漏洞源于头像 alt 属性输出时输入过滤与输出转义不足,攻击者可通过任意用户元数据写入注入脚本。
影响范围
影响该插件所有版本,包括 3.2.1 及更早版本。
漏洞详情
漏洞属于存储型 XSS,成因是插件对用户元数据写入缺乏充分过滤,且头像输出分支未做转义。攻击者需链式利用两步:先调用仅校验 nonce 的 dismiss_ajax_call 接口设置 xs_social_profile_image 元数据标志,激活未转义的 img 输出分支;再将显示名称设置为脚本载荷,核心的 ENT_NOQUOTES 处理会保留其未转义状态。
利用条件与风险
利用前提是攻击者拥有订阅者及以上权限的账户,且目标用户访问被注入页面。实战中可窃取会话、篡改页面内容或进行钓鱼,风险中等。
修复建议
建议更新至官方修复版本;临时缓解可限制低权限用户修改显示名称与相关元数据,或对输出进行额外转义。具体修复版本暂无公开信息。
The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Alt Attribute via Arbitrary User Meta Write in all versions up to, and including, 3.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the attacker to chain two steps: invoking the nonce-only dismiss_ajax_call endpoint (nonce accessible to Subscribers via any wp-admin page) to set the xs_social_profile_image meta flag on their own account, which activates the unescaped img output branch in xs_social_get_avatar, and then setting their display name to a script payload that core’s ENT_NOQUOTES handling preserves unescaped.