Olay Raporu · USOM

TR-26-0339 (WordPress Eklenti Güvenlik Bildirimi)

Dil: TR USOM #11478 Aktif

Genel Bilgi

Bazı WordPress eklentilerinde güvenlik zafiyetleri tespit edilmiştir.

Etki

Mevcut zafiyetler nedeniyle hedef sistemlerin siber saldırganlar tarafından saldırıya uğraması ihtimal dahilindedir. CVE kodları şöyledir:

CVE-2026-3011, CVE-2026-5714, CVE-2026-7556, CVE-2026-8981 ve CVE-2026-4986

Çözüm

Siber Güvenlik Başkanlığı, kullanıcı ve sistem yöneticilerine yayınlanan dokümanları incelemelerini ve gerekli önlemlerin ivedilikle alınmasını tavsiye etmektedir.

Kaynaklar

https://plugins.trac.wordpress.org/browser/enable-media-replace/tags/4.1.8/classes/ViewController/UploadViewController.php#L108

https://plugins.trac.wordpress.org/browser/enable-media-replace/tags/4.1.8/views/screen.php#L228

https://www.wordfence.com/threat-intel/vulnerabilities/id/c6e8a78b-01ad-47b2-84e6-4f6ff78c02b6?source=cve

https://plugins.trac.wordpress.org/browser/fv-wordpress-flowplayer/tags/7.5.49.7212/controller/frontend.php#L657

https://plugins.trac.wordpress.org/browser/fv-wordpress-flowplayer/tags/7.5.49.7212/controller/frontend.php#L685

https://plugins.trac.wordpress.org/browser/fv-wordpress-flowplayer/trunk/controller/frontend.php#L657

https://plugins.trac.wordpress.org/browser/fv-wordpress-flowplayer/trunk/controller/frontend.php#L685

https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3522496%40fv-wordpress-flowplayer%2Ftrunk&old=3478883%40fv-wordpress-flowplayer%2Ftrunk&sfp_email=&sfph_mail=

https://www.wordfence.com/threat-intel/vulnerabilities/id/8bcd5259-2e35-41f6-b269-5b679e4eaab9?source=cve

https://wpscan.com/vulnerability/9815b0e6-e411-4a5c-9c63-30bad21da698/