CVE-2026-97660 WPC Product Options for WooCommerce 存储型 XSS 漏洞
影响未授权攻击者可注入恶意脚本,在用户访问页面时执行
WPC Product Options for WooCommerce 插件(WordPress 平台)存在存储型跨站脚本漏洞。由于对 wpcpo-* 数组键的输入净化和输出转义不足,攻击者可通过 multipart 字段名注入任意脚本。该漏洞影响所有 4.0.5 及之前版本。
影响范围
WPC Product Options for WooCommerce 插件所有版本至 4.0.5(含)。
漏洞详情
漏洞类型为存储型 XSS,成因是插件未对 multipart 请求中 Content-Disposition 字段名(以 wpcpo- 开头)进行充分过滤。PHP 的 RFC1867 解析器会原样保留该字段名并存入订单项元数据,导致恶意脚本被持久化存储。未认证攻击者可通过访客结账流程注入脚本,当用户访问被注入页面时脚本执行。
利用条件与风险
利用无需认证,通过访客结账即可触发,实战风险较高,可导致会话劫持、页面篡改等。
修复建议
建议升级至 4.0.5 之后的修复版本;临时缓解可对 wpcpo-* 字段名进行严格过滤或禁用访客结账功能。具体修复版本暂无公开信息。
The WPC Product Options for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via wpcpo-* Array Key via Multipart Field Name in all versions up to, and including, 4.0.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is exploitable via guest checkout without authentication because the malicious payload is embedded in a multipart Content-Disposition field name beginning with ‘wpcpo-‘, which PHP’s RFC1867 parser preserves byte-for-byte and stores into order item meta.