Genel Bilgi
Bazı WordPress eklentilerinde güvenlik zafiyetleri tespit edilmiştir.
Etki
Mevcut zafiyetler nedeniyle hedef sistemlerin siber saldırganlar tarafından saldırıya uğraması ihtimal dahilindedir. CVE kodları şöyledir:
CVE-2026-6177, CVE-2026-8181, CVE-2026-5396, CVE-2026-6417, CVE-2026-5243, CVE-2026-4029, CVE-2026-4030, CVE-2026-4031, CVE-2026-3426, CVE-2026-3425, CVE-2020-37169, CVE-2026-5361, CVE-2026-7648, CVE-2026-7525, CVE-2026-3829, CVE-2025-15345, CVE-2026-6512, CVE-2026-6504, CVE-2026-6145, CVE-2026-6174, CVE-2026-6206 ve CVE-2026-6514
Çözüm
Siber Güvenlik Başkanlığı, kullanıcı ve sistem yöneticilerine yayınlanan dokümanları incelemelerini ve gerekli önlemlerin ivedilikle alınmasını tavsiye etmektedir.
Kaynaklar
https://github.com/Burst-Statistics/burst-statistics/blob/2488d3fa54045e7e5342b0445b9f6b5eaac9ea7c/includes/Frontend/class-mainwp-proxy.php#L385
https://plugins.trac.wordpress.org/browser/burst-statistics/tags/3.4.1.1/includes/Frontend/class-mainwp-proxy.php#L314
https://plugins.trac.wordpress.org/browser/burst-statistics/tags/3.4.1.1/includes/Frontend/class-mainwp-proxy.php#L328
https://plugins.trac.wordpress.org/browser/burst-statistics/tags/3.4.1.1/includes/Frontend/class-mainwp-proxy.php#L336
https://plugins.trac.wordpress.org/browser/burst-statistics/tags/3.4.1.1/includes/Traits/trait-admin-helper.php#L205
https://plugins.trac.wordpress.org/browser/burst-statistics/trunk/includes/Frontend/class-mainwp-proxy.php#L314
https://plugins.trac.wordpress.org/browser/burst-statistics/trunk/includes/Frontend/class-mainwp-proxy.php#L328
https://plugins.trac.wordpress.org/browser/burst-statistics/trunk/includes/Frontend/class-mainwp-proxy.php#L336
https://plugins.trac.wordpress.org/browser/burst-statistics/trunk/includes/Traits/trait-admin-helper.php#L205
https://www.wordfence.com/threat-intel/vulnerabilities/id/8ca830d6-3d3c-4026-85cd-8447b8a568d3?source=cve