CVE-2021-39349
Author Bio Box に報告された脆弱性
中深刻度
4.8CVSS 3.1
3.3.2修正されたバージョン
1.1%30日以内に悪用される確率
今後30日以内に悪用される確率は 1.1% と推定されています(EPSS)。
概要
The Author Bio Box WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient input validation and sanitization via several parameters found in the ~/includes/admin/class-author-bio-box-admin.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 3.3.1. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.
影響を受けるバージョン
- 3.3.1 以下
対処方法
Author Bio Box を 3.3.2 以降に更新してください。これで本脆弱性は解消します。
この脆弱性は実証コードが公開されています。攻撃に利用されやすい状態のため、優先して対応してください。
あなたのサイトは大丈夫ですか?
URLを入力するだけで、実際に使われているプラグインを検出し、 このデータベースと突き合わせて既知の脆弱性が残っていないかを確認できます。登録不要・無料です。
30秒で無料診断する参照
- https://github.com/BigTiger2020/word-press/blob/main/Author%20Bio%20Box.md
- https://plugins.trac.wordpress.org/changeset/2613798/author-bio-box/tags/3.3.2/includes/admin/class-author-bio-box-admin.php
- https://www.wordfence.com/vulnerability-advisories/#CVE-2021-39349
- https://github.com/BigTiger2020/word-press/blob/main/Author%20Bio%20Box.md
- https://plugins.trac.wordpress.org/changeset/2613798/author-bio-box/tags/3.3.2/includes/admin/class-author-bio-box-admin.php
- https://www.wordfence.com/vulnerability-advisories/#CVE-2021-39349