CVE-2024-11848
NitroPack – Performance, Page Speed & Cache Plugin for Core Web Vitals, CDN & Image Optimization に報告された脆弱性
概要
The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nitropack_dismiss_notice_forever' AJAX action in all versions up to, and including, 1.17.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to update arbitrary options to a fixed value of '1' which can activate certain options (e.g., enable user registration) or modify certain options in a way that leads to a denial of service condition.
影響を受けるバージョン
- 0以上 〜 1.17.0以下
対処方法
NitroPack – Performance, Page Speed & Cache Plugin for Core Web Vitals, CDN & Image Optimization を 1.17.6 以降に更新してください。これで本脆弱性は解消します。
あなたのサイトは大丈夫ですか?
URLを入力するだけで、実際に使われているプラグインを検出し、 このデータベースと突き合わせて既知の脆弱性が残っていないかを確認できます。登録不要・無料です。
30秒で無料診断する