Sucuri¤Ï6·î28Æü(Êƹñ»þ´Ö)¡¢¡ÖWordPress Vulnerability & Patch Roundup June 2024¡×¤Ë¤ª¤¤¤Æ¡¢2024ǯ6·î¤ËÌÀ¤é¤«¤Ë¤Ê¤Ã¤¿WordPress¤ÎÀȼåÀ­¤ª¤è¤Ó¥»¥­¥å¥ê¥Æ¥£¥Ñ¥Ã¥Á¤Î¾ðÊó¤Ë¤Ä¤¤¤ÆÅÁ¤¨¤¿¡£Sucuri¤ÏWeb¥µ¥¤¥È½êÍ­¼Ô¤ËÂФ·¤Æ¿·¤¿¤Ê¶¼°Ò¤òÇÄ°®¤·¤ÆÂн褷¤Æ¤â¤é¤¨¤ë¤è¤¦1¤«·î´Ö¤ÎWordPress¥¨¥³¥·¥¹¥Æ¥à¤Î½ÅÍפʥ»¥­¥å¥ê¥Æ¥£¥¢¥Ã¥×¥Ç¡¼¥È¤ÈÀȼåÀ­¥Ñ¥Ã¥Á¤Î°ìÍ÷¤ò¤Þ¤È¤á¤Æ¸øɽ¤·¤Æ¤¤¤ë¡£

WordPress Vulnerability & Patch Roundup June 2024

º£·î¤Ï40·ï¤ÎÀȼåÀ­¤È¤½¤Î´ËϺö¤¬¾Ò²ð¤µ¤ì¤Æ¤¤¤ë¡£¥»¥­¥å¥ê¥Æ¥£¥ê¥¹¥¯¤¬¡Ö¶ÛµÞ(Critical)¡×¤Èɾ²Á¤µ¤ì¤Æ¤¤¤ë¥½¥Õ¥È¥¦¥§¥¢¤Ï2·ï¡¢¡Ö½ÅÍ×(High)¡×¤Ï3·ï¡¢¡Ö·Ù¹ð(Medium)¡×¤Ï24·ï¡¢¡ÖÄã(Low)¡×¤Ï11·ï¤È¤Ê¤Ã¤Æ¤¤¤ë¡£

¡û6·îWordPress¥×¥é¥°¥¤¥ó¤Î¼ç¤ÊÀȼåÀ­

º£·î¤Î¼ç¤ÊÀȼåÀ­¤Ï¼¡¤Î¤È¤ª¤ê¡£

[¶ÛµÞ(Critical)] CVE-2024-37252 Email Subscribers by Icegram Express - SQL¥¤¥ó¥¸¥§¥¯¥·¥ç¥ó¤ÎÀȼåÀ­

[¶ÛµÞ(Critical)] WooCommerce - ¥¯¥í¥¹¥µ¥¤¥È¥¹¥¯¥ê¥×¥Æ¥£¥ó¥°¤ÎÀȼåÀ­ (XSS)

[½ÅÍ×(High)] CVE-2024-3105 Woody code snippets - ¥ê¥â¡¼¥È¥³¡¼¥É¼Â¹Ô(RCE: Remote Code Execution)¤ÎÀȼåÀ­

[½ÅÍ×(High)] CVE-2024-3549 Blog2Social: Social Media Auto Post - SQL¥¤¥ó¥¸¥§¥¯¥·¥ç¥ó¤ÎÀȼåÀ­

[½ÅÍ×(High)] CVE-2023-6696¡¢CVE-2024-2544 Popup Builder - ¥Ö¥é¥¤¥ó¥É¥µ¡¼¥Ð¡¼¥µ¥¤¥É¥ê¥¯¥¨¥¹¥È¥Õ¥©¡¼¥¸¥§¥ê¡¼(SSRF: Server-Side Request Forgery)¤Î¥»¥­¥å¥ê¥Æ¥£ÀȼåÀ­¤ª¤è¤ÓÉÔŬÀڤʥ¢¥¯¥»¥¹À©¸æ¤Ë¤è¤ëÀȼåÀ­

[·Ù¹ð(Medium)] CVE-2022-44581 Defender Security - ÉÔŬÀÚ¤Êǧ¾Ú¤ÎÀȼåÀ­

[·Ù¹ð(Medium)] CVE-2023-3352 Smush Image Optimization - ÉÔŬÀڤʥ¢¥¯¥»¥¹À©¸æ¤Ë¤è¤ëÀȼåÀ­

[·Ù¹ð(Medium)] CVE-2023-6692 Ultimate Blocks - ¥¯¥í¥¹¥µ¥¤¥È¥¹¥¯¥ê¥×¥Æ¥£¥ó¥°¤ÎÀȼåÀ­ (XSS)

[·Ù¹ð(Medium)] CVE-2024-1168 SEOPress - ¥¯¥í¥¹¥µ¥¤¥È¥¹¥¯¥ê¥×¥Æ¥£¥ó¥°¤ÎÀȼåÀ­ (XSS)

[·Ù¹ð(Medium)] CVE-2024-1766 Download Manager - ¥¯¥í¥¹¥µ¥¤¥È¥¹¥¯¥ê¥×¥Æ¥£¥ó¥°¤ÎÀȼåÀ­ (XSS)

[·Ù¹ð(Medium)] CVE-2024-2473 WPS Hide Login - ÈëÆ¿¤µ¤ì¤¿¥í¥°¥¤¥ó¥Ú¡¼¥¸³«¼¨¤ÎÀȼåÀ­

[·Ù¹ð(Medium)] CVE-2024-2484 Orbit Fox by ThemeIsle - ¥¯¥í¥¹¥µ¥¤¥È¥¹¥¯¥ê¥×¥Æ¥£¥ó¥°¤ÎÀȼåÀ­ (XSS)

[·Ù¹ð(Medium)] CVE-2024-37252 Email Subscribers by Icegram Express - SQL¥¤¥ó¥¸¥§¥¯¥·¥ç¥ó¤ÎÀȼåÀ­

[·Ù¹ð(Medium)] CVE-2024-4390 Slider & Popup Builder by Depicter - ÉÔŬÀڤʥ¢¥¯¥»¥¹À©¸æ¤Ë¤è¤ëÀȼåÀ­

[·Ù¹ð(Medium)] CVE-2024-4479 Jeg Elementor Kit - ¥¯¥í¥¹¥µ¥¤¥È¥¹¥¯¥ê¥×¥Æ¥£¥ó¥°¤ÎÀȼåÀ­ (XSS)

[·Ù¹ð(Medium)] CVE-2024-4632 WooCommerce Checkout & Funnel Builder by CartFlows - ¥¯¥í¥¹¥µ¥¤¥È¥¹¥¯¥ê¥×¥Æ¥£¥ó¥°¤ÎÀȼåÀ­ (XSS)

[·Ù¹ð(Medium)] CVE-2024-4863 Gutenberg Blocks with AI by Kadence WP - ¥¯¥í¥¹¥µ¥¤¥È¥¹¥¯¥ê¥×¥Æ¥£¥ó¥°¤ÎÀȼåÀ­ (XSS)

[·Ù¹ð(Medium)] CVE-2024-5036 Sina Extension for Elementor - ¥¯¥í¥¹¥µ¥¤¥È¥¹¥¯¥ê¥×¥Æ¥£¥ó¥°¤ÎÀȼåÀ­ (XSS)

[·Ù¹ð(Medium)] CVE-2024-5090 SiteOrigin Widgets Bundle - ¥¯¥í¥¹¥µ¥¤¥È¥¹¥¯¥ê¥×¥Æ¥£¥ó¥°¤ÎÀȼåÀ­ (XSS)

[·Ù¹ð(Medium)] CVE-2024-5189 Essential Addons for Elementor - ¥¯¥í¥¹¥µ¥¤¥È¥¹¥¯¥ê¥×¥Æ¥£¥ó¥°¤ÎÀȼåÀ­ (XSS)

[·Ù¹ð(Medium)] CVE-2024-5530 ShopLentor - ¥¯¥í¥¹¥µ¥¤¥È¥¹¥¯¥ê¥×¥Æ¥£¥ó¥°¤ÎÀȼåÀ­ (XSS)

[·Ù¹ð(Medium)] CVE-2024-5531 Ocean Extra - ¥¯¥í¥¹¥µ¥¤¥È¥¹¥¯¥ê¥×¥Æ¥£¥ó¥°¤ÎÀȼåÀ­ (XSS)

[·Ù¹ð(Medium)] CVE-2024-5553 Premium Addons for Elementor - ¥¯¥í¥¹¥µ¥¤¥È¥¹¥¯¥ê¥×¥Æ¥£¥ó¥°¤ÎÀȼåÀ­ (XSS)

[·Ù¹ð(Medium)] CVE-2024-5584 WordPress Online Booking and Scheduling Plugin - Bookly - ¥¯¥í¥¹¥µ¥¤¥È¥¹¥¯¥ê¥×¥Æ¥£¥ó¥°¤ÎÀȼåÀ­ (XSS)

[·Ù¹ð(Medium)] CVE-2024-5605 Media Library Assistant - SQL¥¤¥ó¥¸¥§¥¯¥·¥ç¥ó¤ÎÀȼåÀ­

[·Ù¹ð(Medium)] CVE-2024-5757 Elementor Header & Footer Builder - ¥¯¥í¥¹¥µ¥¤¥È¥¹¥¯¥ê¥×¥Æ¥£¥ó¥°¤ÎÀȼåÀ­ (XSS)

[·Ù¹ð(Medium)] CVE-2024-5787 PowerPack Addons for Elementor - ¥¯¥í¥¹¥µ¥¤¥È¥¹¥¯¥ê¥×¥Æ¥£¥ó¥°¤ÎÀȼåÀ­ (XSS)

[·Ù¹ð(Medium)] CVE-2024-5994 WP Go Maps - ¥¯¥í¥¹¥µ¥¤¥È¥¹¥¯¥ê¥×¥Æ¥£¥ó¥°¤ÎÀȼåÀ­ (XSS)

[·Ù¹ð(Medium)] CVE-2022-44593 Solid Security - ¿®ÍêÀ­¤ÎÄ㤤¥½¡¼¥¹»ÈÍѤÎÀȼåÀ­

[Ãí°Õ(Low)] CVE-2022-44587 WP 2FA - µ¡Ì©¾ðÊóϳ¤¨¤¤¤ÎÀȼåÀ­

[Ãí°Õ(Low)] CVE-2024-0789 WP Maintenance - ¥á¥ó¥Æ¥Ê¥ó¥¹¥â¡¼¥É¥Ð¥¤¥Ñ¥¹¤ÎÀȼåÀ­

[Ãí°Õ(Low)] CVE-2024-2122 FooGallery - ¥¯¥í¥¹¥µ¥¤¥È¥¹¥¯¥ê¥×¥Æ¥£¥ó¥°¤ÎÀȼåÀ­ (XSS)

[Ãí°Õ(Low)] CVE-2024-3492 Events Manager - Calendar, Bookings, Tickets, and more! - ¥¯¥í¥¹¥µ¥¤¥È¥¹¥¯¥ê¥×¥Æ¥£¥ó¥°¤ÎÀȼåÀ­ (XSS)

[Ãí°Õ(Low)] CVE-2024-37881 SiteGuard WP Plugin - ÈëÆ¿¤µ¤ì¤¿¥í¥°¥¤¥ó¥Ú¡¼¥¸³«¼¨¤ÎÀȼåÀ­

[Ãí°Õ(Low)] CVE-2024-3961 ConvertKit - ÉÔŬÀڤʥ¢¥¯¥»¥¹À©¸æ¤Ë¤è¤ëÀȼåÀ­

[Ãí°Õ(Low)] CVE-2024-4145 Search & Replace - SQL¥¤¥ó¥¸¥§¥¯¥·¥ç¥ó¤ÎÀȼåÀ­

[Ãí°Õ(Low)] CVE-2024-4149 Floating Chat Widget - Chaty - ¥¯¥í¥¹¥µ¥¤¥È¥¹¥¯¥ê¥×¥Æ¥£¥ó¥°¤ÎÀȼåÀ­ (XSS)

[Ãí°Õ(Low)] CVE-2024-4266 MetForm - µ¡Ì©¾ðÊóϳ¤¨¤¤¤ÎÀȼåÀ­

[Ãí°Õ(Low)] CVE-2024-4924 Sassy Social Share - ¥¯¥í¥¹¥µ¥¤¥È¥¹¥¯¥ê¥×¥Æ¥£¥ó¥°¤ÎÀȼåÀ­ (XSS)

[Ãí°Õ(Low)] CVE-2024-5639 User Profile Picture - ÉÔŬÀڤʥ¢¥¯¥»¥¹À©¸æ¤Ë¤è¤ëÀȼåÀ­

WordPress¤ÎÀȼåÀ­¤Ï¥µ¥¤¥Ð¡¼¥»¥­¥å¥ê¥Æ¥£ÈȺá¼Ô¤Ë°­ÍѤµ¤ì¤ä¤¹¤¤¡£Web¥µ¥¤¥È¤ò±¿±Ä¤·¤Æ¤¤¤ë¥æ¡¼¥¶¡¼¤Ï¡¢Sucuri¤Î¥»¥­¥å¥ê¥Æ¥£¾ðÊó¤ÎÆâÍƤò³Îǧ¤¹¤ë¤È¤È¤â¤Ë¡¢Å¬Àڤ˴ËϺö¤ÎŬÍѤ䥢¥Ã¥×¥Ç¡¼¥È¤ÎŬÍѤò¼Â»Ü¤¹¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤ë¡£