WF-8a2186c9-fa27-4d7d-be41-c82711c49334
User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission に報告された脆弱性
概要
The WP User Frontend plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'wpuf_file_upload' and 'wpuf_insert_image' AJAX actions in versions before 2.3.11. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server which may make remote code execution possible.
影響を受けるバージョン
- 2.3.11 未満
対処方法
User Frontend – Membership, User Registration, User Profile, User Directory & Content Restriction with Frontend Post Submission を 2.3.11 以降に更新してください。これで本脆弱性は解消します。
あなたのサイトは大丈夫ですか?
URLを入力するだけで、実際に使われているプラグインを検出し、 このデータベースと突き合わせて既知の脆弱性が残っていないかを確認できます。登録不要・無料です。
30秒で無料診断する