Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE に脆弱性 — CVE-2026-4945
いま何をすべきか
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE を 3.1.8 以降に更新してください。
影響を受けるバージョン
- 3.1.7 以下のすべて
対象: プラグイン「Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE」(otter-blocks)
何が起きるのか
The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.1.7 via the 'watch_checkout' function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to pay for a lower-cost product while obtaining entitlement for a premium product by manipulating the product_id parameter independently of the price_id parameter in the Stripe checkout URL.
ここから先の選択肢
1. 自分たちで対応する
更新の手順、バックアップの取り方、壊れたときの戻し方をまとめています。
2. いまの制作会社・保守業者に頼む
Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE を使っているかどうかを含めて確認を依頼してください。 無料診断を実行すると、そのまま渡せる依頼文を作れます。
3. 相談先がない・自分では難しい
連絡が取れる相手がいない、管理画面に入れない、侵入された疑いがある。 そうした場合はご相談ください。
出典
- https://plugins.trac.wordpress.org/browser/otter-blocks/trunk/inc/plugins/class-stripe-api.php#L234
- https://plugins.trac.wordpress.org/browser/otter-blocks/trunk/inc/plugins/class-stripe-api.php#L304
- https://plugins.trac.wordpress.org/browser/otter-blocks/trunk/inc/render/class-stripe-checkout-block.php#L69
- https://plugins.trac.wordpress.org/changeset/3496611/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/7ecb9f61-68d5-4c70-8d7d-e4fb067fcff9?source=cve