在 Super Payments WordPress 插件 1.43.1 版本之前,该插件未能正确验证传入的支付 Webhook 通知的真实性。由于用于验证签名的密钥默认为空,未经身份验证的攻击者可以伪造有效的签名,从而无需实际付款即可将任意 WooCommerce 订单标记为已支付。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Super Payments | 0 ~ 1.43.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89235 | 6.8 MEDIUM | Testimonials by BestWebSoft 1.0.5 - 1.0.8 - Unauthenticated SQLi via 'offset' Parameter |
| CVE-2026-86851 | 6.5 MEDIUM | Livees Checkout 6.8 - 7.0.2 - Unauthenticated Order Status Change, Order Note Injection & |
| CVE-2026-87846 | 5.3 MEDIUM | Shipping for Nova Poshta 1.18.7 - 1.19.8 - Unauthenticated Order Shipment Record Deletion |
| CVE-2026-84220 | 4.8 MEDIUM | Kirki < 6.3.2 - Unauthenticated Arbitrary Shortcode Execution via Comments Collection |
| CVE-2026-85348 | 4.3 MEDIUM | GDPR Data Request Form 1.5 - 1.7.1 - DPO Email Update via CSRF |
| CVE-2026-84224 | 4.1 MEDIUM | Kirki < 6.3.2 - Editor+ Blind SSRF via Remote Template URL |
| CVE-2026-106095 | Code Snippets < 3.10.0 - Admin+ Network-Scoped Snippet Activation and Deactivation via upd | |
| CVE-2026-106097 | Code Snippets < 3.10.0 - Admin+ SQLi in Migration Importers Leading to Network-Wide Creden | |
| CVE-2026-93548 | FooSales < 1.43.3 - Subscriber+ Privilege Escalation via User Impersonation | |
| CVE-2026-87841 | UnitechPay <= 1.0.6.3 - Unauthenticated Order Payment Bypass via Unsigned Webhook | |
| CVE-2026-92990 | SendPress <= 1.26.1.20 - Unauthenticated Newsletter Sending Log Disclosure via Hardcoded T | |
| CVE-2026-88931 | Social Web Suite <= 4.1.12 - Unauthenticated Arbitrary Plugin Settings Update | |
| CVE-2026-86850 | SKU Error Fixer for WooCommerce <= 1.0 - Unauthenticated Orphaned Product Variation Deleti | |
| CVE-2025-15700 | AWP Classifieds < 4.4.9 - Admin+ Arbitrary File Upload via ZIP Import | |
| CVE-2026-92989 | SendPress Newsletters <= 1.26.1.20 - Subscriber+ Mailing List Sync and Newsletter Queueing |
No comments yet