← Back
CVE-2026-4326
high
CVSS 8.8
The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. This is due to improper authorization enforcement in the activate...
Summary
The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. This is due to improper authorization enforcement in the activate_required_plugins() function. Specifically, the current_user_can('install_plugins') capability check...
AI summary openai / gpt-4o
WordPressのVertex Addons for Elementorプラグインのバージョン1.6.4以下には、不適切な認可チェックにより認可不足の脆弱性があります。具体的には、current_user_can('install_plugins')が失敗してもコードの実行が続行され、認証された攻撃者が任意のプラグインをインストールおよび有効化できる可能性があります。
❓ What is the problem
Vertex Addons for Elementorプラグインにおける認可不足の脆弱性。
📍 Affected scope
WordPressのVertex Addons for Elementorプラグイン、バージョン1.6.4以下。
🔥 Severity
認証された攻撃者が任意のプラグインをインストール・有効化できるため、高度の脅威。
🔧 How to fix
必要な認可チェックが失敗した場合に、コードの実行を停止するように修正する。
🛡️ Workaround
特に無し。早急なパッチを適用することが推奨される。
🔍 Detection
バージョン1.6.4以下のVertex Addons for Elementorを使用しているか確認する。
References
- web [email protected]
- web [email protected]
- web [email protected]
- web [email protected]
- web [email protected]
- web [email protected]
- web [email protected]
- web [email protected]
- web [email protected]
- web [email protected]