← 戻る
CVE-2026-3243
high
CVSS 8.8
The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_crop function in all versions up to, and including, 1....
概要
The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_crop function in all versions up to, and including, 1.2.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to...
AI要約 openai / gpt-4o
WordPressのプラグインAdvanced Members for ACFには、バージョン1.2.5を含むそれ以前の全てのバージョンで、create_crop関数におけるファイルパスの不十分な検証により任意のファイル削除の脆弱性があります。この脆弱性を利用して、認証された攻撃者がサーバ上のファイルを削除可能で、特定のファイルが削除されることでリモートコード実行に繋がる可能性があります。
❓ 何が問題か
WordPressプラグインの任意のファイル削除の脆弱性
📍 影響範囲
Advanced Members for ACFプラグインのcreate_crop関数における不適切なファイルパス検証
🔥 重要度
この脆弱性の悪用によりリモートコード実行が可能になり得るため重大です
🔧 修正方法
プラグインを少なくともバージョン1.2.5にアップデートしてください
🛡️ 暫定回避
情報なし
🔍 検知方法
影響を受けるプラグインのバージョンを確認し、使用を避けること
参照URL
- web [email protected]
- web [email protected]
- web [email protected]
- web [email protected]
- web [email protected]
- web [email protected]