目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-92548— WP Popular Posts <= 7.4.2 - Unauthenticated Information Disclosure in 'post_type' and 'context' Parameters

一分钟漏洞结论

影响对象
hcabrera WP Popular Posts
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

WordPress 的 WP Popular Posts 插件在包括 7.4.2 在内的所有版本中,存在敏感信息暴露漏洞。该漏洞通过 参数触发,使得未经身份验证的攻击者能够从非公开的文章对象(例如 WordPress 核心本身拒绝向未认证调用方暴露的 同步模式)中提取敏感的编辑上下文字段,包括原始标题、原始内容正文、密码、元数据(meta)、状态(status)和全局唯一标识符(guid)。 该漏洞之所以可能发生,是因为插件注册的 REST 路由使用了 作为权限回调函数(permission_callback),并

CVSS 5.3 · Medium

可能的 ATT&CK 技术 1 AI

T1592 · Gather Victim Host Information
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-92548 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
WP Popular Posts <= 7.4.2 - Unauthenticated Information Disclosure in 'post_type' and 'context' Parameters
来源: CVE Program / CVE List V5
Vulnerability Description
The WP Popular Posts plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.4.2 via the 'context' parameter. This makes it possible for unauthenticated attackers to extract sensitive edit-context fields — including raw title, raw content body, password, meta, status, and guid — from non-public post objects such as wp_block synced patterns that WordPress core itself refuses to expose to unauthenticated callers. This is possible because the plugin's REST route is registered with a permission_callback of __return_true and passes the caller-supplied context parameter (e.g., context=edit) directly to WP_REST_Posts_Controller::prepare_item_for_response() without invoking get_item_permissions_check() or check_read_permission(), while the underlying query accepts an arbitrary post_type value without enforcing public or show_in_rest visibility flags.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
来源: CVE Program / CVE List V5
Vulnerability Type
信息暴露
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
hcabrera WP Popular Posts 0 ~ 7.4.2 -

二、漏洞 CVE-2026-92548 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-92548 的情报信息

请登录查看更多情报信息。

CVE-2026-92548 其他参考 (7)

IV. Related Vulnerabilities

V. Comments for CVE-2026-92548

暂无评论


发表评论