Liquid Web / StellarWP GiveWP 中存在的缺失授权漏洞允许利用错误配置的访问控制安全级别。此问题影响 GiveWP:从 n/a 到 4.18.0 版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Liquid Web / StellarWP | GiveWP | 0 ~ 4.18.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-66479 | 7.1 HIGH | WordPress WPComplete plugin <= 2.9.5.6 - CSRF to Stored XSS vulnerability |
| CVE-2026-105890 | 6.5 MEDIUM | WordPress Gutenberg Blocks by Kadence Blocks plugin <= 3.7.12 - Cross Site Scripting (XSS) |
| CVE-2026-105888 | 5.4 MEDIUM | WordPress Event Tickets plugin <= 5.30.0.1 - Broken Access Control vulnerability |
| CVE-2026-105893 | 5.3 MEDIUM | WordPress Event Tickets plugin <= 5.30.0.1 - Broken Access Control vulnerability |
| CVE-2026-105891 | 4.3 MEDIUM | WordPress Event Tickets plugin <= 5.30.0.1 - Broken Access Control vulnerability |
No comments yet