版本低于 5.0.1 的 JCH Optimize WordPress 插件未对其管理后台的图片浏览功能中的目录路径进行适当的限制,使得该路径可能超出网站根目录。这使得高权限用户(单站点的管理员)以及多站点环境中的子站点管理员能够枚举 Web 根目录之外的目录和文件名。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | JCH Optimize | 4.2.1 ~ 5.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78362 | SEO Flow by LupsOnline 3.0.0 - 3.0.2 - Unauthenticated Privilege Escalation via API Key Au | |
| CVE-2026-82846 | Masteriyo LMS 1.18.0 - 2.3.3 - Instructor+ Stored XSS via Course Custom Fields | |
| CVE-2026-82304 | Music Store – WordPress eCommerce < 1.4.5 - Unauthenticated SQLi via paypal-data Handler | |
| CVE-2026-81424 | Accept Stripe Payments < 2.1.4 - Unauthenticated Product Substitution via IDOR | |
| CVE-2026-83543 | Greenshift < 13.2.0 - Contributor+ SSRF via get-csv-to-json REST Endpoint | |
| CVE-2026-83544 | Greenshift < 13.2.0 - Contributor+ Stored XSS via Block Animation customProps Attribute | |
| CVE-2026-81423 | Accept Stripe Payments < 2.1.4 - Open Redirect via IPN Handler | |
| CVE-2026-81348 | My Private Site < 4.2.3 - Unauthenticated Sensitive Information Exposure via RSS Feeds and | |
| CVE-2026-81404 | IPGP Visitors Origin < 1.6 - Reflected XSS | |
| CVE-2026-84021 | Bold Page Builder < 5.9.8 - Contributor+ Stored XSS via bt_bb_button/bt_bb_headline/bt_bb_ | |
| CVE-2026-77826 | RegistrationMagic 5.0.1.8 - 6.0.9.8 - Unauthenticated Authentication Bypass via Missing Fa | |
| CVE-2026-78149 | Post Carousel 4.0.0 - 4.0.7 - Unauthenticated Password-Protected Post Content and post_pas | |
| CVE-2026-78150 | Post Carousel 4.0.0 - 4.0.7 - Contributor+ Private and Protected Post Content Disclosure v | |
| CVE-2026-19861 | JetFormBuilder < 3.6.5.2 - Unauthenticated Stored XSS via WYSIWYG Field in Notification Em | |
| CVE-2026-15247 | Search Atlas SEO < 2.6.24 - Subscriber+ Google Service Account Credential Overwrite/Deleti | |
| CVE-2026-19858 | JetFormBuilder < 3.6.5.2 - Unauthenticated Password Hash and Arbitrary Metadata Disclosure | |
| CVE-2025-15694 | Joli Table Of Contents 2.0.0 - 2.8.0 - Admin+ Stored XSS | |
| CVE-2026-84937 | YT Player < 2.1.0 - Contributor+ SQLi via ytp_ajax | |
| CVE-2026-84022 | Bold Page Builder < 5.9.8 - Contributor+ Stored XSS via Multiple Shortcode Element Attribu | |
| CVE-2026-84221 | Kirki 6.0.0 - 6.2.5 - Editor+ SQLi via Content Manager Field ID |
Showing top 20 of 34 CVEs. View all on vendor page → →
No comments yet