← 戻る
Webアプリケーション
CVE-2026-4326 high CVSS 8.8

The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. This is due to improper authorization enforcement in the activate...

概要

The Vertex Addons for Elementor plugin for WordPress is vulnerable to Missing Authorization in all versions up to and including 1.6.4. This is due to improper authorization enforcement in the activate_required_plugins() function. Specifically, the current_user_can('install_plugins') capability check...

AI要約 openai / gpt-4o

WordPressのVertex Addons for Elementorプラグインのバージョン1.6.4以下には、不適切な認可チェックにより認可不足の脆弱性があります。具体的には、current_user_can('install_plugins')が失敗してもコードの実行が続行され、認証された攻撃者が任意のプラグインをインストールおよび有効化できる可能性があります。
❓ 何が問題か
Vertex Addons for Elementorプラグインにおける認可不足の脆弱性。
📍 影響範囲
WordPressのVertex Addons for Elementorプラグイン、バージョン1.6.4以下。
🔥 重要度
認証された攻撃者が任意のプラグインをインストール・有効化できるため、高度の脅威。
🔧 修正方法
必要な認可チェックが失敗した場合に、コードの実行を停止するように修正する。
🛡️ 暫定回避
特に無し。早急なパッチを適用することが推奨される。
🔍 検知方法
バージョン1.6.4以下のVertex Addons for Elementorを使用しているか確認する。

参照URL

🍪 Cookie について

当サイトはログイン状態の保持・言語設定・サービス改善のために Cookie を使用します。詳細は下記リンクをご確認ください。

詳細 →