B
今週中
WordPressプラグイン「The Events Calendar」に、CVSS 9.8の深刻な脆弱性が2件(CVE-2026-78159,…
📌 一言でいうと
WordPressプラグイン「The Events Calendar」に、CVSS 9.8の深刻な脆弱性が2件(CVE-2026-78159, CVE-2026-78006)発見されました。攻撃者は認証なしでコードインジェクションやPHPオブジェクトインジェクションを実行し、サーバー上で任意のコマンドを実行してサイトを完全に制御できる可能性があります。この脆弱性は、イベントページでコメント機能が有効になっている場合に影響を受けます。
🔍該当判定
- WordPressでプラグイン「The Events Calendar」をインストールして利用している
- 「The Events Calendar」のバージョンが 6.17.3.1 未満である
- プラグイン設定の「Show comments on event pages(イベントページにコメントを表示)」を有効にしている
上記いずれにも該当しない → 静観でOK
✅該当時の対応
プラグインを最新バージョン(CVE-2026-78159は6.17.3.1以降、CVE-2026-78006は最新版)にアップデートしてください。不要な場合はイベントページのコメント機能を無効化することを推奨します。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】The Events Calendar (CVE-2026-78159, CVE-2026-78006) 対応について
お疲れさまです。WordPressプラグイン「The Events Calendar」の深刻な脆弱性に関する情報共有です。
■ 概要
CVSS 9.8の脆弱性が2件報告されました。認証されていない攻撃者が、イベントページのコメント機能を通じてコードインジェクションやPHPオブジェクトインジェクションを行い、サーバー上で任意のコマンドを実行してサイトを制御される恐れがあります。
■ 影響範囲
- 対象製品: The Events Calendar (WordPress Plugin)
- 対象バージョン: 6.17.4未満(CVE-2026-78159は6.17.3以下)
- 条件: イベントページのコメント機能("Show comments on event pages")が有効であること
■ 対応手順
1. プラグインを最新バージョン(6.17.3.1以降、およびCVE-2026-78006修正済みの最新版)へアップデートしてください。
2. 不要であれば、プラグイン設定からイベントページのコメント機能を無効化してください。
■ 参考情報
- Wordfence / ThaiCERT アドバイザリ
対応優先度: 高
対応期限: 至急
お疲れさまです。WordPressプラグイン「The Events Calendar」の深刻な脆弱性に関する情報共有です。
■ 概要
CVSS 9.8の脆弱性が2件報告されました。認証されていない攻撃者が、イベントページのコメント機能を通じてコードインジェクションやPHPオブジェクトインジェクションを行い、サーバー上で任意のコマンドを実行してサイトを制御される恐れがあります。
■ 影響範囲
- 対象製品: The Events Calendar (WordPress Plugin)
- 対象バージョン: 6.17.4未満(CVE-2026-78159は6.17.3以下)
- 条件: イベントページのコメント機能("Show comments on event pages")が有効であること
■ 対応手順
1. プラグインを最新バージョン(6.17.3.1以降、およびCVE-2026-78006修正済みの最新版)へアップデートしてください。
2. 不要であれば、プラグイン設定からイベントページのコメント機能を無効化してください。
■ 参考情報
- Wordfence / ThaiCERT アドバイザリ
対応優先度: 高
対応期限: 至急
Subject: [Security Advisory] The Events Calendar (CVE-2026-78159, CVE-2026-78006) Update Required
Dear IT Administrator,
We are sharing critical vulnerability information regarding the 'The Events Calendar' WordPress plugin.
■ Overview
Two critical vulnerabilities (CVSS 9.8) have been identified. Unauthenticated attackers can exploit these via the event page comment section to perform code injection or PHP object injection, potentially leading to remote code execution (RCE) and full site compromise.
■ Scope
- Product: The Events Calendar (WordPress Plugin)
- Affected Versions: Versions prior to 6.17.4 (CVE-2026-78159 affects 6.17.3 and below)
- Condition: The "Show comments on event pages" option must be enabled.
■ Remediation
1. Update the plugin to the latest version (6.17.3.1 or newer).
2. Disable comments on event pages if they are not required for business operations.
■ Reference
- Wordfence / ThaiCERT Advisory
Priority: High
Deadline: Immediate
Dear IT Administrator,
We are sharing critical vulnerability information regarding the 'The Events Calendar' WordPress plugin.
■ Overview
Two critical vulnerabilities (CVSS 9.8) have been identified. Unauthenticated attackers can exploit these via the event page comment section to perform code injection or PHP object injection, potentially leading to remote code execution (RCE) and full site compromise.
■ Scope
- Product: The Events Calendar (WordPress Plugin)
- Affected Versions: Versions prior to 6.17.4 (CVE-2026-78159 affects 6.17.3 and below)
- Condition: The "Show comments on event pages" option must be enabled.
■ Remediation
1. Update the plugin to the latest version (6.17.3.1 or newer).
2. Disable comments on event pages if they are not required for business operations.
■ Reference
- Wordfence / ThaiCERT Advisory
Priority: High
Deadline: Immediate