CVE-2024-13818
Pie Register – User Registration, Profiles & Content Restriction に報告された脆弱性
概要
The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.8.4 through publicly exposed log files. This makes it possible for unauthenticated attackers to view potentially sensitive information about users contained in the exposed log files.
影響を受けるバージョン
- 3.8.3.9 以下
対処方法
Pie Register – User Registration, Profiles & Content Restriction を 3.8.4.1 以降に更新してください。これで本脆弱性は解消します。
Pie Register – User Registration, Profiles & Content Restriction の他の脆弱性を見る →
あなたのサイトは大丈夫ですか?
URLを入力するだけで、実際に使われているプラグインを検出し、 このデータベースと突き合わせて既知の脆弱性が残っていないかを確認できます。登録不要・無料です。
30秒で無料診断する参照
- https://plugins.trac.wordpress.org/browser/pie-register/trunk/classes/base_variables.php#L68
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3255985%40pie-register%2Ftrunk&old=3246810%40pie-register%2Ftrunk&sfp_email=&sfph_mail=
- https://www.wordfence.com/threat-intel/vulnerabilities/id/768730c1-a70e-432d-a234-4ce2b8aec424?source=cve