WordPress Elementor Pro の脆弱性 CVE-2026-32475 が FIX:悪意のある PHP ファイルのアップロードと RCE

Critical WordPress Plugin Vulnerability Exposes Sites to RCE Attacks

2026/08/21 CyberSecurityNews — Elementor Pro WordPress プラグインに存在する深刻なセキュリティ脆弱性を悪用する未認証の攻撃者は、悪意のある PHP ファイルをアップロードし、脆弱なサーバ上でコードを実行する可能性がある。この脆弱性 CVE-2026-32475 は、Elementor Pro バージョン 4.2.1 以下に影響を及ぼし、バージョン 4.2.2 で修正されている。

Continue reading “WordPress Elementor Pro の脆弱性 CVE-2026-32475 が FIX:悪意のある PHP ファイルのアップロードと RCE”

WordPress プラグイン Elementor Pro に深刻な脆弱性:現時点で 1100万サイトにインストール

Hackers exploit bug in Elementor Pro WordPress plugin with 11M installs

2023/03/31 BleepingComputer — 1100万以上の Web サイトで使用されている、人気の WordPress プラグイン Elementor Pro の深刻な脆弱性が、ハッカーたちに積極的に悪用されている。Elementor Pro が提供する機能には、ドラッグ&ドロップ/テーマ構築/テンプレート・コレクション/カスタム・ウィジェットのサポートに加えて、オンライン・ショップ用の WooCommerce ビルダーなどがある。そのため、ユーザーがコードを知らなくても、プロフェッショナルなサイトを簡単に構築できる、WordPress ページ・ビルダー・プラグインとして人気を博している。

Continue reading “WordPress プラグイン Elementor Pro に深刻な脆弱性:現時点で 1100万サイトにインストール”