目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-93485— WordPress 7.1 跨站脚本漏洞

一分钟漏洞结论

影响对象
Automattic WordPress
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

在 Automattic 开发的 WordPress 核心中,存在一个“在网页生成期间未正确中和输入(跨站脚本攻击/XSS)”的漏洞,允许实施基于 DOM 的 XSS(DOM-Based XSS)。 此问题影响以下 WordPress 版本: 7.1 版本至 7.1.1 之前; 7.0 至 7.0.4; 6.9 至 6.9.7; 6.8 至 6.8.8; 6.7 至 6.7.7; 6.6 至 6.6.7; 6.5 至 6.5.10; 6.4 至 6.4.10; 6.3 至 6.3.10; 6.2 至 6.2.11;

CVSS 7.1 · High EPSS 0.16% · P6

影响版本矩阵 25

厂商产品 版本范围状态
Automattic WordPress 7.1< 7.1.1 affected
7.0≤ 7.0.4 affected
6.9≤ 6.9.7 affected
6.8≤ 6.8.8 affected
6.7≤ 6.7.7 affected
6.6≤ 6.6.7 affected
6.5≤ 6.5.10 affected
6.4≤ 6.4.10 affected
… +17 条更多
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-93485 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
WordPress core <= 7.1 - Unauth. Cross Site Scripting (XSS) vulnerability
来源: CVE Program / CVE List V5
Vulnerability Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS. This issue affects WordPress versions 7.1 before 7.1.1; 7.0 through 7.0.4; 6.9 through 6.9.7; 6.8 through 6.8.8; 6.7 through 6.7.7; 6.6 through 6.6.7; 6.5 through 6.5.10; 6.4 through 6.4.10; 6.3 through 6.3.10; 6.2 through 6.2.11; 6.1 through 6.1.12; 6.0 through 6.0.14; 5.9 through 5.9.16; 5.8 through 5.8.15; 5.7 through 5.7.17; 5.6 through 5.6.19; 5.5 through 5.5.20; 5.4 through 5.4.21; 5.3 through 5.3.23; 5.2 through 5.2.26; 5.1 through 5.1.24; 5.0 through 5.0.27; 4.9 through 4.9.31; 4.8 through 4.8.30; and 4.7 through 4.7.35. The Unauthenticated Stored XSS vulnerability in the WordPress core can be reproduced on a default WordPress installation. Comment moderation is disabled by default, and the requirement for commenters to have a previously approved comment can be bypassed.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
来源: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
Automattic WordPress 7.1 ~ 7.1.1 -
Automattic WordPress 7.0 ~ 7.0.4 -
Automattic WordPress 6.9 ~ 6.9.7 -
Automattic WordPress 6.8 ~ 6.8.8 -
Automattic WordPress 6.7 ~ 6.7.7 -
Automattic WordPress 6.6 ~ 6.6.7 -
Automattic WordPress 6.5 ~ 6.5.10 -
Automattic WordPress 6.4 ~ 6.4.10 -
Automattic WordPress 6.3 ~ 6.3.10 -
Automattic WordPress 6.2 ~ 6.2.11 -
Automattic WordPress 6.1 ~ 6.1.12 -
Automattic WordPress 6.0 ~ 6.0.14 -
Automattic WordPress 5.9 ~ 5.9.16 -
Automattic WordPress 5.8 ~ 5.8.15 -
Automattic WordPress 5.7 ~ 5.7.17 -
Automattic WordPress 5.6 ~ 5.6.19 -
Automattic WordPress 5.5 ~ 5.5.20 -
Automattic WordPress 5.4 ~ 5.4.21 -
Automattic WordPress 5.3 ~ 5.3.23 -
Automattic WordPress 5.2 ~ 5.2.26 -
Automattic WordPress 5.1 ~ 5.1.24 -
Automattic WordPress 5.0 ~ 5.0.27 -
Automattic WordPress 4.9 ~ 4.9.31 -
Automattic WordPress 4.8 ~ 4.8.30 -
Automattic WordPress 4.7 ~ 4.7.35 -

二、漏洞 CVE-2026-93485 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-93485 的情报信息

登录查看更多情报信息。

CVE-2026-93485 厂商安全公告 (1)

CVE-2026-93485 其他参考 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-93485

暂无评论


发表评论