WP脆弱性ウォッチ脆弱性データ 2026年8月28日 時点

CVE-2026-58480

Blocksy Companion に報告された脆弱性

緊急深刻度
9.2CVSS 4.0
未公表修正されたバージョン
3.6%30日以内に悪用される確率
今後30日以内に悪用される確率は 3.6% と推定されています(EPSS)。

概要

Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upload executable files by bypassing extension validation in the save_attachments function exposed through the Advanced Reviews feature. Attackers can exploit the Custom Fonts extension's flawed strpos() substring check by uploading double-extension filenames such as shell.woff2.php, causing the validation to pass on the substring match while the web server executes the file as PHP, achieving remote code execution.

CWE: CWE-434 / 公開 2026年7月8日 / 最終更新 2026年7月8日

影響を受けるバージョン

対処方法

修正版が公表されていません。最新版への更新、無効化、または代替プラグインへの移行を検討してください。

Blocksy Companion の他の脆弱性を見る →

あなたのサイトは大丈夫ですか?

URLを入力するだけで、実際に使われているプラグインを検出し、 このデータベースと突き合わせて既知の脆弱性が残っていないかを確認できます。登録不要・無料です。

30秒で無料診断する

参照