← Back
Web Application
CVE-2026-14279 high CVSS 8.8

The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...

Summary

The Wholesale Market plugin for WordPress is vulnerable to privilege escalation in versions up to...

AI summary openai / gpt-4o

WordPress用Wholesale Marketプラグインのバージョン2.2.2以下には、privilege escalationの脆弱性があります。この脆弱性は、認証された攻撃者が管理者権限を取得するために利用される可能性があります。
❓ What is the problem
WordPressのWholesale Marketプラグインにおける権限昇格の脆弱性。
📍 Affected scope
プラグインのバージョン2.2.2以下。
🔥 Severity
攻撃者が管理者権限を不正に取得できるため、重要。
🔧 How to fix
プラグインのアップデートで脆弱性を修正。
🛡️ Workaround
管理者はプラグインの設定を確認し、必要な設定を制限する。
🔍 Detection
WP_User::add_role()が不適切に呼び出されているか検査する。

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →