← Back
CVE-2026-16601
high
CVSS 8.8
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
Summary
The CM Map Locations – Visualize and share your locations in a few clicks plugin for WordPress is...
AI summary openai / gpt-4o
WordPressのプラグイン「CM Map Locations」は、バージョン2.1.8までで、任意のファイルを意図しない形でアップロード可能な脆弱性を抱えています。これにより、認証された攻撃者が悪意のあるファイルをアップロードし、リモートコードの実行が可能になります。
❓ What is the problem
WordPressのCM Map Locationsプラグインにおける任意のファイルアップロードの脆弱性
📍 Affected scope
バージョン2.1.8までのCM Map Locationsプラグイン
🔥 Severity
攻撃者が実行可能なファイルをアップロードしリモートコードを実行可能であるため、重大
🔧 How to fix
プラグインをバージョン2.1.9以上に更新する
🛡️ Workaround
プラグインの利用を一時停止するか、無効化する
🔍 Detection
プラグインのバージョンを確認し、バージョン2.1.8以下であれば影響を受ける可能性がある
References
- web [email protected]
- web [email protected]
- web [email protected]
- web [email protected]
- web [email protected]
- web [email protected]
- web [email protected]
- web [email protected]
- web [email protected]
- web https://nvd.nist.gov/vuln/detail/CVE-2026-16601
- web https://github.com/advisories/GHSA-5ph3-fc6c-c54j