CVE-2023-45751
Nexter Extension – Security, Performance, Code Snippets & Site Toolkit に報告された脆弱性
高深刻度
7.2CVSS
2.0.4修正されたバージョン
0.6%30日以内に悪用される確率
概要
The Nexter Extension plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.0.3 via the nxt-code-php-snippet metabox. This allows authenticated attackers with editor-level privileges and above to execute code on the server.
影響を受けるバージョン
- 2.0.3 以下
対処方法
Nexter Extension – Security, Performance, Code Snippets & Site Toolkit を 2.0.4 以降に更新してください。これで本脆弱性は解消します。
Nexter Extension – Security, Performance, Code Snippets & Site Toolkit の他の脆弱性を見る →
あなたのサイトは大丈夫ですか?
URLを入力するだけで、実際に使われているプラグインを検出し、 このデータベースと突き合わせて既知の脆弱性が残っていないかを確認できます。登録不要・無料です。
30秒で無料診断する