WF-78759abf-4584-4beb-9ae7-39a5c3fe4b75
YARPP – Yet Another Related Posts Plugin に報告された脆弱性
緊急深刻度
9.8CVSS
4.2.5修正されたバージョン
—30日以内に悪用される確率
概要
The YARPP – Yet Another Related Posts Plugin for WordPress is vulnerable a Cross-Site Request Forgery which can lead to Remote Code Execution in versions up to, and including, 4.2.4 via the yarpp_options.php file. This allows unauthenticated attackers to execute code on the server if they can successfully trick an administrator into performing an action such as clicking on a link.
影響を受けるバージョン
- 4.2.5 未満
対処方法
YARPP – Yet Another Related Posts Plugin を 4.2.5 以降に更新してください。これで本脆弱性は解消します。
あなたのサイトは大丈夫ですか?
URLを入力するだけで、実際に使われているプラグインを検出し、 このデータベースと突き合わせて既知の脆弱性が残っていないかを確認できます。登録不要・無料です。
30秒で無料診断する