- Katılım
- 12 Şub 2024
- Mesajlar
- 69
Genel Bilgi
Bazı WordPress eklentilerinde güvenlik zafiyetleri tespit edilmiştir.
Etki
Mevcut zafiyetler nedeniyle hedef sistemlerin siber saldırganlar tarafından saldırıya uğraması ihtimal dahilindedir. CVE kodları şöyledir:
CVE-2026-11351, CVE-2026-16585, CVE-2026-45293, CVE-2026-16587, CVE-2026-15671, CVE-2026-14516, CVE-2026-16774, CVE-2026-13110, CVE-2026-15444, CVE-2026-14328, CVE-2026-12800, CVE-2026-15014, CVE-2026-15136, CVE-2026-11598, CVE-2026-12741, CVE-2026-15012, CVE-2026-15411, CVE-2026-6251, CVE-2026-15016, CVE-2026-14490, CVE-2026-12124, CVE-2026-10207, CVE-2026-14545, CVE-2026-15025, CVE-2026-15393, CVE-2026-14819, CVE-2026-14821, CVE-2026-14924, CVE-2026-14926, CVE-2026-16797, CVE-2026-15673, CVE-2026-15267, CVE-2026-13440, CVE-2026-16773, CVE-2026-14785, CVE-2026-13161, CVE-2026-15730, CVE-2026-15670, CVE-2026-14870, CVE-2026-16811, CVE-2026-17161, CVE-2026-17162, CVE-2026-17166, CVE-2026-12144, CVE-2026-12939, CVE-2026-12938, CVE-2026-15735, CVE-2026-18072, CVE-2026-14300, CVE-2026-14234, CVE-2026-14224, CVE-2026-13692, CVE-2026-13690, CVE-2026-13605, CVE-2026-13423, CVE-2026-11974 ve CVE-2026-9690
Çözüm
Siber Güvenlik Başkanlığı, kullanıcı ve sistem yöneticilerine yayınlanan dokümanları incelemelerini ve gerekli önlemlerin ivedilikle alınmasını tavsiye etmektedir.
Kaynaklar
https://github.com/WordPress/WordPr...mmit/a29048d0bbef5cf25d42349c74e4072d3cbc8325
https://github.com/WordPress/WordPress-Coding-Standards/pull/2771
https://github.com/WordPress/WordPress-Coding-Standards/releases/tag/3.4.1
https://github.com/WordPress/WordPress-Coding-Standards/security/advisories/GHSA-3pwp-g2mj-5p3v
https://plugins.trac.wordpress.org/...n/tags/2.6.0/platforms/mailup/mailup.php#L375
https://plugins.trac.wordpress.org/...n/tags/2.6.0/platforms/mailup/mailup.php#L411
https://plugins.trac.wordpress.org/...on/tags/2.6.0/platforms/mailup/mailup.php#L51
https://plugins.trac.wordpress.org/...on/tags/2.6.0/platforms/mailup/mailup.php#L98
https://plugins.trac.wordpress.org/...gration&new=3621411@advanced-form-integration
https://www.wordfence.com/threat-in...913bb1-eff6-47cd-9471-f74bafda1e52?source=cve
