← 戻る
CVE-2026-3445
high
CVSS 7.1
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to unauthorized membership payment bypass i...
概要
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to unauthorized membership payment bypass in all versions up to, and including, 4.16.11. This is due to a missing ownership verification on the...
AI要約 openai / gpt-4o
WordPressのProfilePressプラグインは、バージョン4.16.11まで、未承認のメンバーシップ支払いバイパスの脆弱性があります。認証された攻撃者が他のユーザーのサブスクリプションを利用して、支払いなしに有料プランを取得できる恐れがあります。
❓ 何が問題か
ProfilePressプラグインの未承認のメンバーシップ支払いバイパス脆弱性。
📍 影響範囲
WordPressのProfilePressプラグインバージョン4.16.11まで。
🔥 重要度
認証された攻撃者が支払いなしに有料の会員プランを取得できるため、高いセキュリティリスクがあります。CVSSスコアは7.1です。
🔧 修正方法
ProfilePressプラグインを最新版にアップデートすることで修正可能です。
🛡️ 暫定回避
特に無し。迅速にプラグインを更新することを推奨します。
🔍 検知方法
プラグインのバージョンを確認し、4.16.11以前であれば影響を受ける可能性があります。
参照URL
- web [email protected]
- web [email protected]