CVE-2022-4950
Cool Timeline (Horizontal & Vertical Timeline) に報告された脆弱性
高深刻度
8.8CVSS 3.1
2.4修正されたバージョン
1.4%30日以内に悪用される確率
今後30日以内に悪用される確率は 1.4% と推定されています(EPSS)。
概要
Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.
影響を受けるバージョン
- 2.4 未満
- 2.5.1 未満
- 1.3 未満
- 1.6 未満
- 1.2 未満
- 2.0 未満
- 1.5 未満
- 1.4 未満
- 1.8 未満
対処方法
Cool Timeline (Horizontal & Vertical Timeline) を 2.4 以降に更新してください。これで本脆弱性は解消します。
あなたのサイトは大丈夫ですか?
URLを入力するだけで、実際に使われているプラグインを検出し、 このデータベースと突き合わせて既知の脆弱性が残っていないかを確認できます。登録不要・無料です。
30秒で無料診断する参照
- https://blog.nintechnet.com/8-wordpress-plugins-fixed-high-severity-vulnerability/
- https://plugins.trac.wordpress.org/changeset/2705076/cool-timeline/trunk/admin/timeline-addon-page/timeline-addon-page.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/f6f0fb78-ad6b-4a9e-ae1a-5793f3426379?source=cve
- https://blog.nintechnet.com/8-wordpress-plugins-fixed-high-severity-vulnerability/
- https://plugins.trac.wordpress.org/changeset/2705076/cool-timeline/trunk/admin/timeline-addon-page/timeline-addon-page.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/f6f0fb78-ad6b-4a9e-ae1a-5793f3426379?source=cve