# 内部链接构建器 1.0 存储型 XSS 漏洞
## 概述
The Internal Link Builder WordPress 插件在所有版本(包括 1.0 版本)中存在存储型跨站脚本漏洞,攻击者可通过管理界面注入恶意脚本。
## 影响版本
所有版本至 1.0(含 1.0)。
## 细节
漏洞源于插件在管理员设置中缺乏充分的输入过滤和输出转义,导致攻击者可提交恶意 JavaScript 脚本并持久化存储。当其他用户访问包含注入内容的页面时,脚本将自动执行。
## 影响
仅影响多站点(multi-site)安装,且在 `unfiltered_html` 被禁用的情况下生效。具有管理员或更高级别权限的已认证攻击者可利用此漏洞实施 XSS 攻击,危害用户会话安全或进行权限劫持。
是否为 Web 类漏洞: 未知
判断理由:
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
标题: Internal Link Builder <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via Plugin's Settings -- 🔗来源链接
标签:
神龙速读:
### Vulnerability Details for Internal Link Builder
- **CVE ID**: CVE-2025-14725
- **CVSS Score**: 4.4 (Medium)
- **Publicly Published**: January 13, 2026
- **Last Updated**: January 14, 2026
- **Researcher**: 0x34rth
#### Description
The Internal Link Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
#### References
- [plugins.trac.wordpress.org](plugins.trac.wordpress.org)
#### Vulnerability Details
| Field | Value |
|------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------|
| Software Type | Plugin |
| Software Slug | internal-link-builder (view on wordpress.org) |
| Patched? | No |
| Remediation | No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. |
| Affected Version | <= 1.0 |
Zaproxy alias impedit expedita quisquam pariatur exercitationem. Nemo rerum eveniet dolores rem quia dignissimos.