→ برگشت به فید آسیبپذیریها
CVE-2026-13709 · graphina-elementor-charts-and-graphs
تزریق اسکریپت ذخیرهشده (Stored XSS) در افزونه Graphina – Charts and Graphs For Elementor
افزونه Graphina – Charts and Graphs For Elementor تا نسخه ۳.۱.۱۱ به دلیل sanitization ناکافی ورودی و escaping خروجی در تنظیمات ویجت iq_tree_tree_chart_template آسیبپذیر به تزریق اسکریپت ذخیرهشده است. مهاجمان احراز هویتشده با سطح دسترسی Contributor و بالاتر میتوانند اسکریپتهای مخرب را در صفحات تزریق کنند که هنگام بازدید کاربران اجرا شده و منجر به سرقت نشست یا اجرای کد مخرب میشود. با توجه به وجود وصله امنیتی، افزونه را فوراً به نسخه امن بهروزرسانی کنید.
نسخههای تحت تأثیر
<= 3.1.11
راهنمای اقدام و رفع مشکل (Remediation)
- ۱. پشتیبانگیری: قبل از اعمال هرگونه تغییر، یک بکاپ کامل از پایگاه داده و فایلهای سایت تهیه کنید.
- ۲. بهروزرسانی سریع: افزونه یا هسته graphina-elementor-charts-and-graphs را بلافاصله به آخرین نسخه ارائهشده ارتقا دهید.
- ۳. فایروال و مانیتورینگ: در صورت عدم امکان آپدیت فوری، رولهای امنیتی WAF را فعال کرده و لاگهای وبسرور را پایش نمایید.
مراجع رسمی و مستندات
- https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/tags/3.1.11/assets/elementor/js/apex-tree/TreeChart.js#L146 ↗
- https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/tags/3.1.11/includes/Charts/Elementor/GraphinaElementorControls.php#L1446 ↗
- https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/tags/3.1.11/includes/GraphinaFunction.php#L1653 ↗
- https://plugins.trac.wordpress.org/browser/graphina-elementor-charts-and-graphs/tags/3.1.11/templates/graphina-apex-tree/tree-chart.php#L19 ↗
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3553477%40graphina-elementor-charts-and-graphs&new=3553477%40graphina-elementor-charts-and-graphs ↗
- https://www.wordfence.com/threat-intel/vulnerabilities/id/fb99c935-947e-43a2-8291-c6a0724f8610?source=cve ↗