- Katılım
- 12 Şub 2024
- Mesajlar
- 243
Genel Bilgi
Bazı WordPress eklentilerinde güvenlik zafiyetleri tespit edilmiştir.
Etki
Mevcut zafiyetler nedeniyle hedef sistemlerin siber saldırganlar tarafından saldırıya uğraması ihtimal dahilindedir. CVE kodları şöyledir:
CVE-2026-15413, CVE-2026-14332, CVE-2026-3639, CVE-2026-73353, CVE-2026-73346, CVE-2026-66697, CVE-2026-66655, CVE-2026-66468, CVE-2026-66466, CVE-2026-66462, CVE-2026-66461, CVE-2026-66436, CVE-2026-66431, CVE-2026-27345, CVE-2026-12743, CVE-2026-12949, CVE-2026-16810 ve CVE-2025-10308
Çözüm
Siber Güvenlik Başkanlığı, kullanıcı ve sistem yöneticilerine yayınlanan dokümanları incelemelerini ve gerekli önlemlerin ivedilikle alınmasını tavsiye etmektedir.
Kaynaklar
https://plugins.trac.wordpress.org/...ncludes/services/class-ppw-shortcode.php#L582
https://plugins.trac.wordpress.org/...tcode/view-ppw-restriced-content-form.php#L18
https://plugins.trac.wordpress.org/...ncludes/services/class-ppw-shortcode.php#L582
https://plugins.trac.wordpress.org/...tcode/view-ppw-restriced-content-form.php#L18
https://plugins.trac.wordpress.org/...9&new_path=/password-protect-page/tags/1.9.20
https://www.wordfence.com/threat-in...a5206e-8888-4872-b4bd-91fe5628498c?source=cve
https://patchstack.com/database/wor...broken-access-control-vulnerability?_s_id=cve
https://patchstack.com/database/wor...gin-6-2-sql-injection-vulnerability?_s_id=cve
https://patchstack.com/database/wor...ss-site-scripting-xss-vulnerability?_s_id=cve
https://patchstack.com/database/wor...ss-site-scripting-xss-vulnerability?_s_id=cve
https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/
