← Retour
CVE-2026-15991
high
CVSS 8.8
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible...
Résumé
The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary f...
Résumé IA openai / gpt-4o
Une vulnérabilité référencée **CVE-2026-15991** a été découverte dans wordpress.
L'exploitation peut entraîner la prise de contrôle totale du système. Score CVSS : 8.8/10.
Action : appliquez le correctif officiel de l'éditeur.
En cas de doute, contactez votre service informatique ou cherchez « wordpress CVE-2026-15991 » sur le site de l'éditeur.
CVE-2026-15991 (wordpress) — CWE-862 / CVSS v3 8.8
Vecteur d'attaque : distant (réseau) / sans interaction utilisateur
Plan : 1) Audit SBOM, 2) Mise à jour staging→prod, 3) Surveillance WAF/proxy sur les endpoints affectés, 4) Recherche d'IOC dans les logs.
Réfs : voir GHSA / avis éditeur / version corrigée liés sur cette page.
❓ Quel est le problème
任意のファイル削除が可能な脆弱性
📍 Périmètre concerné
WordPress用File Managerプラグイン(バージョン6.0から6.9)
🔥 Gravité
認証された攻撃者がリモートコード実行を引き起こす可能性があり、深刻な影響を与える。
🔧 Comment corriger
プラグインのバージョンを6.9.1以降にアップグレードしてください。
🛡️ Contournement
適切なファイルパスのバリデーションを追加するか、影響のある機能を無効化してください。
🔍 Détection
サーバーログを分析し、異常なファイル操作がないか確認する。
Références
- web [email protected]
- web [email protected]
- web [email protected]
- web [email protected]
- web [email protected]
- web [email protected]
- web [email protected]
- web [email protected]
- web [email protected]