CVE-2021-39341
Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation に報告された脆弱性
概要
The OptinMonster WordPress plugin is vulnerable to sensitive information disclosure and unauthorized setting updates due to insufficient authorization validation via the logged_in_or_has_api_key function in the ~/OMAPI/RestApi.php file that can used to exploit inject malicious web scripts on sites with the plugin installed. This affects versions up to, and including, 2.6.4.
影響を受けるバージョン
- 2.6.4 以下
対処方法
Popup Builder & Popup Maker for WordPress – OptinMonster Email Marketing and Lead Generation を 2.6.5 以降に更新してください。これで本脆弱性は解消します。
この脆弱性は実証コードが公開されています。攻撃に利用されやすい状態のため、優先して対応してください。
あなたのサイトは大丈夫ですか?
URLを入力するだけで、実際に使われているプラグインを検出し、 このデータベースと突き合わせて既知の脆弱性が残っていないかを確認できます。登録不要・無料です。
30秒で無料診断する参照
- https://plugins.trac.wordpress.org/browser/optinmonster/trunk/OMAPI/RestApi.php?rev=2606519#L1460
- https://wordfence.com/vulnerability-advisories/#CVE-2021-39341
- https://www.wordfence.com/blog/2021/10/1000000-sites-affected-by-optinmonster-vulnerabilities/
- https://plugins.trac.wordpress.org/browser/optinmonster/trunk/OMAPI/RestApi.php?rev=2606519#L1460
- https://wordfence.com/vulnerability-advisories/#CVE-2021-39341
- https://www.wordfence.com/blog/2021/10/1000000-sites-affected-by-optinmonster-vulnerabilities/