Info o zraniteľnostiach WP

Interná informácia pre weby v našej správe  (detekované zraniteľnosti)

Input validation vulnerability in WordPress 6.3.1

CVE-2023-38000
Severity: medium-risk
Status: Fixed
Publication: October 12, 2023
WordPress has identified a security vulnerability in versions 5.9 to 6.3.1 that allows malicious attackers with contributor-level privileges or higher to inject malicious scripts into pages that will execute when a user accesses them. This vulnerability is caused by a lack of input sanitization and output escaping when using arrow navigation block attributes. It is important for users of WordPress Core 5.9 to 6.3.1 to update their software as soon as possible to prevent malicious attackers from exploiting this vulnerability.

Detected in:
Gutenberg Stav: fixed, Vulnerable Versions: >= * <= 16.8.0
WordPress Stav: fixed Vulnerable Versions: >= 5.9 <= 6.3.1
info z: https://really-simple-ssl.com/vulnerability/ae1dc4b2-9a3a-4afb-a06f-3d0c2d5d0d97/

Aktualizovať na verziu: 6.3.2

Access violation vulnerability in WooCommerce 7.8.2
Severity: medium-risk
Status: Fixed
Publication: September 11, 2023
The WooCommerce plugin for WordPress is not secure in versions up to and including 7.8.2. This security risk could allow unauthorised people to access sensitive user information like Personal Identifiable Information (PII) without any authentication. This is because the Store API’s REST endpoints do not properly restrict external access from any origin.

Detected in:
WooCommerce Stav: fixed
Vulnerable Versions: >= * <= 7.8.2

info z: https://really-simple-ssl.com/vulnerability/723c8fdb-dcce-4a97-95d0-907138172b27/

Aktualizovať na verziu: 7.9.0

 

Predchádzajúci článok
Štítky na webe pri importe z Realsoftu

Súvisiace príspevky