WF-6c3032ae-eb86-47d0-b160-320a67a380e1
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema に報告された脆弱性
概要
The WooCommerce Reviews Plugin with Multi-criteria Rating by ReviewX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 1.2.9. This is due to missing nonce validation in the ~/app/Controllers/Storefront/ReviewxPublic.php file. This makes it possible for unauthenticated attackers to perform unauthorized AJAX actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
影響を受けるバージョン
- 1.2.9 未満
対処方法
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema を 1.2.9 以降に更新してください。これで本脆弱性は解消します。
ReviewX – Multi-Criteria Reviews for WooCommerce with Google Reviews & Schema の他の脆弱性を見る →
あなたのサイトは大丈夫ですか?
URLを入力するだけで、実際に使われているプラグインを検出し、 このデータベースと突き合わせて既知の脆弱性が残っていないかを確認できます。登録不要・無料です。
30秒で無料診断する