JVN#67963942 WordPressç¨ãã©ã°ã¤ã³Advanced Custom Fieldsã«ãããã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ã®èå¼±æ§
JVN#67963942 WordPressç¨ãã©ã°ã¤ã³Advanced Custom Fieldsã«ãããã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ã®èå¼±æ§
JVN#60331535 WordPressç¨ãã©ã°ã¤ã³SiteGuard WP Pluginã«ãããå¤æ´ãããã°ã¤ã³ãã¹ãæ¼ããããèå¼±æ§ EGã»ãã¥ã¢ã½ãªã¥ã¼ã·ã§ã³ãºãæä¾ããWordPressç¨ãã©ã°ã¤ã³SiteGuard WP Pluginã«ã¯ãå¤æ´ãããã°ã¤ã³ãã¹ã¸ã®ã¢ã¯ã»ã¹ããâä»ã®ãã¼ã¸ããã®ãªãã¤ã¬ã¯ãã«ããå¯è½ã«ãªãèå¼±æ§ãåå¨ãã¾ãã
JVN#98946408 WordPress ç¨ãã©ã°ã¤ã³ Advanced Custom Fields ã«ãããã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ã®èå¼±æ§
JVN#90560760 WordPress ç¨ãã©ã°ã¤ã³ TS Webfonts for ãããã®ã¬ã³ã¿ã«ãµã¼ãã«ãããè¤æ°ã®èå¼±æ§ ãããã¤ã³ã¿ã¼ãããæ ªå¼ä¼ç¤¾ãæä¾ãã WordPress ç¨ãã©ã°ã¤ã³ TS Webfonts for ãããã®ã¬ã³ã¿ã«ãµã¼ãã«ã¯ãè¤æ°ã®èå¼±æ§ãåå¨ãã¾ãã CVE-2023-32624 TS Webfonts for ãããã®ã¬ã³ã¿ã«ãµã¼ã 3.1.0 ããã³ãã以å CVE-2023-32625 TS Webfonts for ãããã®ã¬ã³ã¿ã«ãµã¼ã 3.1.2 ããã³ãã以å
JVN#01093915 WordPress ç¨ãã©ã°ã¤ã³ MW WP Form ããã³ Snow Monkey Forms ã«ãããè¤æ°ã®èå¼±æ§ æ ªå¼ä¼ç¤¾ã¢ã³ãã¼ã¬ã³ããæä¾ãã WordPress ç¨ãã©ã°ã¤ã³ MW WP Form ããã³ Snow Monkey Forms ã«ã¯ãè¤æ°ã®èå¼±æ§ãåå¨ãã¾ãã CVE-2023-28408ãCVE-2023-28409 MW WP Form v4.4.2 ããã³ãã以åã®ãã¼ã¸ã§ã³ CVE-2023-28413 Snow Monkey Forms v5.0.6 ããã³ãã以åã®ãã¼ã¸ã§ã³
ãµã¼ã証ææ¸ã®çºè¡ãæªç¨ããWordPressã§ä½ããããµã¤ããã¿ã¼ã²ããã«ããæ»æãææããã¦ããï¼The Daily Swigãmatsuuåºäºæ®µããã®ãã¤ã¼ãï¼ã The Daily Swig ã®è¨äºã«ããã°ããã®æ»æã¯Certificate Transparencyï¼CTï¼ã·ã¹ãã ãæªç¨ãããã®ãCTã§ã¯ä¸æ£ãªè¨¼ææ¸ãè¿ éã«çºè¦ããããã証ææ¸ãç´ã¡ã«å ¬éãã°ã«è¨é²ãããã¨ã義åã¥ãããã¦ãããä»åææããã¦ããæ»æã§ã¯ãæªæã®ããããã«ã¼ãå ã®å ¬éãã°ãç£è¦ããWordPressã®æ°è¦ãã¡ã¤ã³ãæ¤åºããã¨å³åº§ã«ã¢ã¯ã»ã¹ãåæã¤ã³ã¹ãã¼ã«ç¶æ ã®WordPressã«ããã¯ãã¢ãä»æããã¨ããææ³ã§ããããã ã ãã®æ»æã«ãããTLS証ææ¸ãè¦æ±ããã¦ããæ°ç§ããæ°åã®ãã¡ã«ãµã¤ãããããã³ã°ãããã¨ãã証è¨ãè¤æ°åºã¦ãã¦ããã¨ã®ãã¨ã証ææ¸èªè¨¼å±ã®Let's Encryptã®Josh
JVN#42543427 WordPress ç¨ãã©ã°ã¤ã³ Advanced Custom Fields ã«ãããèªè¨¼æ¬ å¦ã®èå¼±æ§
ãããä¸ã«åå¨ããå ¨ã¦ã§ããµã¤ãã®ãã¡43.3ï¼ ã§å©ç¨ããã¦ããã¨ããããã°ã½ããã¦ã§ã¢ã»WordPressã«ããã¦ãåè¨90以ä¸ã®ãã¼ãããã©ã°ã¤ã³ã«ãã¦ã§ããµã¤ãã¸ã®ä¸æ£ã¢ã¯ã»ã¹ãå¯è½ã«ããããã¯ãã¢ãä»è¾¼ã¾ãã¦ãããã¨ããããã¾ããã Backdoor Found in Themes and Plugins from AccessPress Themes https://jetpack.com/2022/01/18/backdoor-found-in-themes-and-plugins-from-accesspress-themes/ AccessPress Themes Hit With Targeted Supply Chain Attack https://blog.sucuri.net/2022/01/accesspress-themes-hit-with-targeted
JVN#09136401 WordPress ç¨ãã©ã°ã¤ã³ Advanced Custom Fields ã«ãããè¤æ°ã®èªè¨¼æ¬ å¦ã®èå¼±æ§
by Kaitlyn Baker 2017å¹´11æã«å ¥ã£ã¦jQueryãGoogle Analyticsã®ã³ã¼ãã«è¦ãããã¦ãã¤ãã³ã°ç¨ã¹ã¯ãªãããèªã¿è¾¼ã¾ããã¨ãããã«ã¦ã§ã¢ãcloudflare[.]solutionããæµè¡ãã¦ãã¾ãã11ææç¹ã§ã¯ææãµã¤ãæ°ã¯1833ã ã£ãã®ã§ããããã®å¾ããã«ã¦ã§ã¢ã¯é²åãã¦ãã¼ãã¬ã¼ã®æ©è½ãåãè¾¼ã¿ãææãµã¤ãæ°ã5500ã«è¿«ã£ã¦ãããã¨ããããã¾ããã Cloudflare[.]Solutions Keylogger on Thousands of Infected WordPress Sites https://blog.sucuri.net/2017/12/cloudflare-solutions-keylogger-on-thousands-of-infected-wordpress-sites.html Hacked Websites
by Peter Hershey ãªã¼ãã³ã½ã¼ã¹ã®ããã°ã½ããã¦ã§ã¢ã»WordPressã§ããCaptchaããã©ã°ã¤ã³ã«ããã¯ãã¢ãåå¨ãããµã¤ãã®ç®¡çã¢ã¯ã»ã¹æ¨©ãä¸æ£ã«åå¾ã§ããç¶æ ã ã£ããã¨ããããã¾ããããã§ã«ãã©ã°ã¤ã³ããããã¯ãã¢ã¯åé¤ããã¦ãã¾ãã Backdoor in Captcha Plugin Affects 300K WordPress Sites https://www.wordfence.com/blog/2017/12/backdoor-captcha-plugin/ Hidden Backdoor Found In WordPress Captcha Plugin Affects Over 300,000 Sites https://thehackernews.com/2017/12/wordpress-security-plugin.html WordPr
WordPressãå¤é¨ãã容æã«æ¹ããã§ããèå¼±æ§ã®æ å ±é示ãè¡ãããåé¡ã§ãã¢ãããã¼ããæªå®æ½ã ã£ããµã¤ãã«è¢«å®³ãæ¡å¤§ãã¦ãããããæ»æãã£ã³ãã¼ã³ã§ã¯ã2æ¥éã§æ°ä¸ä»¶ã®ãã¼ã¸ã被害ã«éã£ãã¨è¦ããã¦ããã åèå¼±æ§ãçºè¦ãå ¬è¡¨ããSucuriããå社ã®ã¦ã§ãã¢ããªã±ã¼ã·ã§ã³ãã¡ã¤ã¢ã¦ã©ã¼ã«ï¼WAFï¼ãããã¼ãããã«å¯¾ããæ»æç¶æ³ãªã©ãè¸ã¾ããèå¼±æ§å ¬éå¾ã®ç¶æ³ãæ»æçºçç¶æ³ãªã©ãåãã¾ã¨ãããã®ã èå¼±æ§æ å ±ã®å ¬éãã2æ¥ãçµããã«ãªã³ã©ã¤ã³ä¸ã§ã¯è¤æ°ã®æ»æã³ã¼ããæ稿ãå ±æããã¦ããç¶æ³ã§ãæ»æè ãèå¼±æ§ã«é¢ãã詳細ãªæ å ±ã容æã«å ¥æã§ããç¶æ ã«ããã¨èª¬æã å¾ã ã«èå¼±æ§ãæªä¿®æ£ã®ã¦ã§ããµã¤ãã®æ¢ç´¢ãæªç¨ãæ¡å¤§ãå社ã®WAFã«ããæ¤ç¥æ°ãå¢å ã辿ã£ã¦ããã2æ6æ¥ã«ã¯3000件弱ã®æ»æãæ¤ç¥ããã¨ãã¦ããã ã¾ãä»åã®èå¼±æ§ã«é¢é£ããå社ãææ¡ãã¦ããã ãã§å°ãªãã¨ã4種é¡ã®æ»æ
ã¨ã°ã¼ã¯ãã£ããµã㪠WordPress 4.7ã¨4.7.1ã®REST APIã«ãèªè¨¼ãåé¿ãã¦ã³ã³ãã³ããæ¸ãæããããèå¼±æ§ãåå¨ãããæ»æã¯æ¥µãã¦å®¹æã§ããã®å½±é¿ã¯ä»»æã³ã³ãã³ãã®æ¸ãæãã§ãããããé大ãªçµæãåã¼ãã対çã¯WordPressã®ææ°çã«ãã¼ã¸ã§ã³ã¢ãããããã¨ã§ããã æ¬ç¨¿ã§ã¯ãèå¼±æ§æ··å ¥ã®åå ã«ã¤ãã¦å ±åããã ã¯ããã« WordPressæ¬ä½ã«ä¹ ãã¶ãã«é大ãªèå¼±æ§ãè¦ã¤ãã£ãã¨çºè¡¨ããã¾ããã ãããªé¢¨ã«æ¸ãã¨ãWordPressã®èå¼±æ§ãªãã¦ããã£ã¡ã ãè¦ã¤ãã£ã¦ããã¨ããæè¦ãããããã§ãããè½åçãã¤èªè¨¼ãªãã«ãä¾µå ¥ã§ããèå¼±æ§ã¯ããæ°å¹´åºã¦ããªãããã«æãã¾ããããããã¯ã©ã¹ã®ãã®ãä¹ ãã¶ãã«è¦ã¤ãã£ãã¨ãããã¨ã§ããã WordPressãæ´æ°çã§æ·±å»ãªèå¼±æ§ãä¿®æ£ãå®å ¨ç¢ºä¿ã®ããæ å ±å ¬éãå éã Make WordPress Core Conten
2016å¹´12æ25æ¥ãPHPã®ã¡ã¼ã«éä¿¡ã©ã¤ãã©ãªPHPMailerã«ä»»æã®ã³ã¼ãå®è¡å¯è½ãªèå¼±æ§ã確èªãããã¨ãã¦æ å ±ãå ¬éããã¾ãããããã§ã¯èå¼±æ§ã®é¢é£æ å ±ãã¾ã¨ãã¾ãã èå¼±æ§ã®æ¦è¦ 対象 PHPMailer CVE CVE-2016-10033 CVE-2016-10045 å½±é¿ RCE éè¦åº¦ Critical(çºè¦è ) ç·æ¥(JVN) CVSS JPCERT/CCè©ä¾¡ CVSSv3ï¼5.4 (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N) CVSSv2ï¼5.5 (AV:N/AC:L/Au:S/C:P/I:P/A:N) PoC ã¤ã³ã¿ã¼ãããä¸ã«å ¬éæ¸ CVE-2016-10033â2016/12/26 CVE-2016-10045â2016/12/28 çºè¦è /å ±åè CVE-2016-10033:Dawid Golunskiæ°(
ãããææ¸ã®æµåºåå ã¯ãWordpressã®ãã©ã°ã¤ã³ï¼ ã»ãã¥ãªãã£ãç©´ã ããã ã£ããã¨ãå¤æ2016.04.11 13:005,428 渡éå¾¹å æãã¬ã¨ããã«ç©´ãâ¦ã ä¸çä¸ã®æ¿æ²»å®¶ãçµæ¸äººãèåã¹ãã¼ãé¸æãªã©ãããããï½¢ä¸çãããã®å¤§éæã¡ï½£ãã¡ãã¿ãã¯ã¹ãã¤ãã³ã§è³ç£ãé ãã¦ããã®ã§ã¯ãªããã¨ããçæãæµ®ä¸ããããããææ¸åé¡ããã®çç¸ããããããã¾ã ä¸çãæºãããç¶ãã¦ãã¾ãã ãã®æ å ±ã®æµåºå ã«ã¤ãã¦ã¯ãå é¨ã®ä½è ãã«ãããªã¼ã¯ï¼æ¼æ´©ï¼èª¬ã¨ãï½¢ãªã¼ã¯ã§ã¯ãªãããã¯ï½£ã ã¨ãã説ãåããã¦ãã¾ããçç¸ã¯ã¾ã ä¸æãªãããããããã¯ã ã¨ããããWordpressã®ãã©ã°ã¤ã³ãåå ã§ããå¯è½æ§ãæµ®ä¸ãã¾ããã ãã®ãã©ã°ã¤ã³ã®åã¯ï½¢Revolution Sliderï½£ã以åãSlider Revolutionã¨ãããã©ã°ã¤ã³ãçã£ããã·ã¢ã®ãã«ã¦ã§ã¢ãããã¾ããããããã¨åæ§ããµã¤ã
WordPressåãã«æä¾ããã¦ããè¤æ°ã®ãã©ã°ã¤ã³ãããã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ã®èå¼±æ§ãè¦ã¤ãã£ã¦ããã¨ãã¦ãã»ãã¥ãªãã£ãã³ãã¼ã注æãå¼ã³ããã¦ãããé¢æ°ã®èª¤ä½¿ç¨ã«èµ·å ããå¤æ°ã®ãã©ã°ã¤ã³ãå½±é¿ãåãã¦ããã¨ããã ç±³Sucuriã«ããã¨ãåé¡ã®èå¼±æ§ã¯ã4æ13æ¥ã®é±ã«å¤æãããã®ã§ãé¢æ°ãadd_query_arg()ããremove_query_arg()ãã®ä½¿ç¨æ¹æ³ã«èµ·å ãå ¬å¼ããã¥ã¡ã³ãã«ããè¨è¼ãä¸æ確ã§ãå¤ãã®ãã©ã°ã¤ã³éçºè ãå®å ¨ã§ã¯ãªãæ¹æ³ã§é¢æ°ãç¨ãã¦ããã¨å社ã¯ææãã¦ããã å®éã«å½±é¿ãåãããã©ã°ã¤ã³ãè¦ãã¨ããWordPress SEOããGoogle Analytics by YoastããAll In one SEOããªã©SEOæ©è½ãæä¾ãããã©ã°ã¤ã³ã®ã»ããã¹ãã¼ããã©ã³åãã®ã¤ã³ã¿ãã§ã¼ã¹ãæä¾ãããWPTouchãããªã³ã¯ã®ãã§ãã¯æ©è½ã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}