CVE-2024-25933
PeproDev Ultimate Invoice に報告された脆弱性
高深刻度
7.5CVSS
1.9.8修正されたバージョン
0.5%30日以内に悪用される確率
概要
The PeproDev Ultimate Invoice plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.9.7 via the 'init_plugin' function. This makes it possible for unauthenticated attackers to generate PDF or ZIP files of arbitrary invoices and extract sensitive data.
影響を受けるバージョン
- 1.9.7 以下
対処方法
PeproDev Ultimate Invoice を 1.9.8 以降に更新してください。これで本脆弱性は解消します。
あなたのサイトは大丈夫ですか?
URLを入力するだけで、実際に使われているプラグインを検出し、 このデータベースと突き合わせて既知の脆弱性が残っていないかを確認できます。登録不要・無料です。
30秒で無料診断する