كل الثغرات
متوسطCVE-2026-7640
ثغرة XSS في WP Customer Area
38
درجة الخطر
6.4
CVSS
0%
EPSS
CWE-79
التصنيف
الوصف
ثغرة تخزين XSS في إضافة WP Customer Area عبر خاصية 'type' في shortcode، مما يسمح للمهاجمين بإدخال نصوص برمجية تنفذ عند زيارة الصفحات المصابة.
يجري إعداد تحليل الذكاء الاصطناعي لهذه الثغرة… سيظهر قريباً.
المعالجة الموصى بها
حدّث المنتج المتأثّر إلى أحدث إصدار مُصحَّح من المورّد، وراجع المصادر الرسمية أدناه للحصول على المعالجة الدقيقة.
المصادر والمراجع الرسمية
https://plugins.trac.wordpress.org/browser/customer-area/tags/8.3.4/src/php/core-addons/shortcodes/shortcodes/protected-content-shortcode.class.php#L90 https://plugins.trac.wordpress.org/browser/customer-area/tags/8.3.6/src/php/core-addons/shortcodes/shortcodes/protected-content-shortcode.class.php#L88-L91 https://plugins.trac.wordpress.org/browser/customer-area/trunk/src/php/core-addons/shortcodes/shortcodes/protected-content-shortcode.class.php#L90 https://wordpress.org/plugins/customer-area https://www.wordfence.com/threat-intel/vulnerabilities/id/c6f96cec-ddcb-45b2-a28c-b4e7b6f5c719?source=cve NVD — CVE-2026-7640
نُشرت: 2026-07-14