WordPress插件“Code Snippets”在3.10.0版本之前,在某个片段管理操作中未执行权限检查,并且它根据请求来确定目标片段的网络作用域,而不是从存储的记录中获取。这导致多站点网络中单个子站的管理员可以激活、停用和重新排序作用于整个网络的所有站点的网络级片段。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Code Snippets | 0 ~ 3.10.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84220 | 4.8 MEDIUM | Kirki < 6.3.2 - Unauthenticated Arbitrary Shortcode Execution via Comments Collection |
| CVE-2026-84224 | 4.1 MEDIUM | Kirki < 6.3.2 - Editor+ Blind SSRF via Remote Template URL |
| CVE-2026-106097 | Code Snippets < 3.10.0 - Admin+ SQLi in Migration Importers Leading to Network-Wide Creden | |
| CVE-2026-93548 | FooSales < 1.43.3 - Subscriber+ Privilege Escalation via User Impersonation | |
| CVE-2026-87841 | UnitechPay <= 1.0.6.3 - Unauthenticated Order Payment Bypass via Unsigned Webhook | |
| CVE-2026-92990 | SendPress <= 1.26.1.20 - Unauthenticated Newsletter Sending Log Disclosure via Hardcoded T | |
| CVE-2026-88931 | Social Web Suite <= 4.1.12 - Unauthenticated Arbitrary Plugin Settings Update | |
| CVE-2026-86850 | SKU Error Fixer for WooCommerce <= 1.0 - Unauthenticated Orphaned Product Variation Deleti | |
| CVE-2025-15700 | AWP Classifieds < 4.4.9 - Admin+ Arbitrary File Upload via ZIP Import | |
| CVE-2026-92989 | SendPress Newsletters <= 1.26.1.20 - Subscriber+ Mailing List Sync and Newsletter Queueing |
No comments yet