← Back
Web Application
CVE-2026-3243 high CVSS 8.8

The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_crop function in all versions up to, and including, 1....

Summary

The Advanced Members for ACF plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the create_crop function in all versions up to, and including, 1.2.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to...

AI summary openai / gpt-4o

WordPressのプラグインAdvanced Members for ACFには、バージョン1.2.5を含むそれ以前の全てのバージョンで、create_crop関数におけるファイルパスの不十分な検証により任意のファイル削除の脆弱性があります。この脆弱性を利用して、認証された攻撃者がサーバ上のファイルを削除可能で、特定のファイルが削除されることでリモートコード実行に繋がる可能性があります。
❓ What is the problem
WordPressプラグインの任意のファイル削除の脆弱性
📍 Affected scope
Advanced Members for ACFプラグインのcreate_crop関数における不適切なファイルパス検証
🔥 Severity
この脆弱性の悪用によりリモートコード実行が可能になり得るため重大です
🔧 How to fix
プラグインを少なくともバージョン1.2.5にアップデートしてください
🛡️ Workaround
情報なし
🔍 Detection
影響を受けるプラグインのバージョンを確認し、使用を避けること

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →