Ultimate Multisite WordPress 插件在 2.17.0 版本之前存在安全漏洞。该漏洞允许未认证的攻击者在注销结账流程中,将结账会话链接到并登录为与提交的电子邮件地址匹配的现有 WordPress 账户。由于该插件在重复账户检查时对电子邮件地址的规范化处理方式与创建客户记录时的查找方式不一致,攻击者可以通过已知邮箱地址以任意现有用户(包括网络超级管理员)的身份登录。 此绕过问题并未被 CVE-2026-75957 在 2.15.1 版本中的修复所解决,且在所有包含 2.15.1 修复版本预期的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Ultimate Multisite | 0 ~ 2.17.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93509 | 6.5 MEDIUM | Wallet System for WooCommerce 2.0.0 - 2.7.10 - Subscriber+ Wallet Balance Manipulation via |
| CVE-2026-103517 | 5.3 MEDIUM | Airwallex Online Payments Gateway < 1.36.0 - Unauthenticated Payment Bypass via Forged Web |
| CVE-2026-104671 | 5.3 MEDIUM | TutorStarter < 4.0.4 - Unauthenticated User Registration Bypass via AJAX |
| CVE-2026-105190 | 5.3 MEDIUM | Easy Digital Downloads < 3.7.1 - Unauthenticated Account Creation with Registration Disabl |
| CVE-2026-103309 | GPTranslate < 2.34.14 - Unauthenticated Stored XSS via REST API Translation Storage | |
| CVE-2026-104646 | Image Photo Gallery Final Tiles Grid < 3.6.14 - Contributor+ Stored XSS via Gallery Shortc | |
| CVE-2026-104645 | Image Photo Gallery Final Tiles Grid < 3.6.14 - Contributor+ Arbitrary Gallery Cloning, Im | |
| CVE-2026-103692 | Frontend Dashboard 3.0.0 - 3.0.4 - Unauthenticated Privilege Escalation via Arbitrary Func | |
| CVE-2026-105195 | Booking Calendar 10.15 - 11.8.2 - Editor+ Arbitrary Option Disclosure | |
| CVE-2026-105197 | LatePoint < 5.6.5 - Agent+ Arbitrary Order, Customer and Transaction Deletion via IDOR | |
| CVE-2026-105198 | LatePoint < 5.7.3 - Unauthenticated Customer PII Disclosure via IDOR | |
| CVE-2026-105194 | Easy Digital Downloads < 3.7.1 - Subscriber+ Sensitive Information Disclosure via User Dow | |
| CVE-2026-105196 | LatePoint < 5.6.9 - Agent+ Cross-Agent Data Disclosure and Modification via Abilities API | |
| CVE-2026-105193 | Booking Calendar < 11.8 - Unauthenticated Booking Information Disclosure and Modification | |
| CVE-2026-86826 | BackWPup < 5.7.7 - Unauthenticated Sensitive Data Disclosure via Restore Working Directory | |
| CVE-2026-86827 | BackWPup 3.3 - 5.7.6 - Unauthenticated Backup Job Execution via wp-cron.php | |
| CVE-2026-86828 | BackWPup < 5.7.7 - Admin+ Path Traversal to RCE via Restore PclZip Fallback | |
| CVE-2026-105260 | Database Addon For WPForms < 1.1.1 - Arbitrary Form Entry Deletion via CSRF | |
| CVE-2026-94246 | Wallet System for WooCommerce 2.0.0 - 2.7.10 - Subscriber+ Forged Wallet Withdrawal Reques | |
| CVE-2026-94244 | Wallet System for WooCommerce < 2.8.0 - Subscriber+ Store-Wide Wallet Transaction Disclosu |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet