Frontend Dashboard WordPress 插件在 3.0.0 版本之前,其中一个 AJAX 操作未执行权限检查,导致具有低权限的已认证用户(例如“订阅者”)能够删除该插件所配置的用户资料字段和文章表单字段。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Frontend Dashboard | < 3.0.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Frontend Dashboard | 0 ~ 3.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82211 | 8.2 HIGH | Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Completion and Order Key Disclosure |
| CVE-2026-82212 | 7.5 HIGH | Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Bypass via NPG Notification Handler |
| CVE-2026-86833 | 5.4 MEDIUM | MetForm < 4.3.1 - Unauthenticated HTML Injection in Notification Emails via Field Shortcod |
| CVE-2026-105322 | 5.3 MEDIUM | Magee Shortcodes <= 2.1.1 - Unauthenticated Mail Relay via Contact Form |
| CVE-2026-103323 | Integration for Epos Now and WooCommerce 4.6.0 - 4.11.1 - Unauthenticated Action Scheduler | |
| CVE-2026-104049 | Academy LMS < 4.0.0 - Subscriber+ Arbitrary Lesson Content Disclosure via Topic REST Endpo | |
| CVE-2026-104651 | Yaad Sarig Payment Gateway For WC < 2.2.13 - Subscriber+ Arbitrary Order Payment Manipulat | |
| CVE-2026-104652 | Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Image ID | |
| CVE-2026-104050 | Academy LMS < 4.0.0 - Subscriber+ Cross-Course Quiz Answer Disclosure via render_quiz_answ | |
| CVE-2026-103378 | Geliver Akıllı Kargo Pazaryeri 3.0.0 - 3.1.0 - Unauthenticated API Key Disclosure via Publ | |
| CVE-2026-104653 | Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Crop Dimensions | |
| CVE-2026-104953 | MPG < 4.2.3 - Editor+ SQLi via Project Import | |
| CVE-2026-104677 | WP Coder 4.0 - 4.5.1 - Editor+ RCE via Global PHP | |
| CVE-2026-104667 | Animated Number Counters < 3.1 - Editor+ Second-Order SQLi via Counter Order | |
| CVE-2026-104678 | CP Media Player < 1.3.4 - Contributor+ Media Player Settings Update | |
| CVE-2026-105316 | Magee Shortcodes <= 2.1.1 - Reflected XSS via live_preview and magee_create_shortcode Acti | |
| CVE-2026-86816 | WPCafe < 3.0.21 - Unauthenticated Product Data Disclosure via REST API | |
| CVE-2026-87971 | If-So Dynamic Content 1.4.4 - 1.10.1 - Reflected XSS via 'message' Parameter | |
| CVE-2026-87782 | Koinonia Link 1.1.2 - 1.1.4 - Subscriber+ Privilege Escalation to Administrator | |
| CVE-2026-97188 | String Locator < 2.6.8 - Unauthenticated PHP Object Injection via Database Editor |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet