plugin-planet user submitted posts是plugin-planet个人开发者开源的一套用户提交内容插件。 Jeff Starr User Submitted Posts 20260608之前版本存在跨站脚本漏洞,该漏洞源于未对提交的值进行转义,导致存储型跨站脚本攻击,可在启用非默认显示选项时由未经验证的用户触发。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | User Submitted Posts | < 20260608 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | User Submitted Posts | 0 ~ 20260608 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11568 | Product Configurator for WooCommerce < 1.7.3 - Unauthenticated Private/Draft Product Data | |
| CVE-2026-11562 | WS Form LITE < 1.11.8 - Subscriber+ Arbitrary Settings Update | |
| CVE-2026-11794 | Advanced Form Integration < 2.1.1 - Unauthenticated Privilege Escalation via Breakdance Fo | |
| CVE-2026-10750 | Royal MCP < 1.4.26 - Subscriber+ Insufficient Authorization in MCP Tools | |
| CVE-2026-11887 | Salon Booking System < 10.30.20 - Subscriber+ Booking Approval Bypass | |
| CVE-2026-11880 | Fluent Forms < 6.2.1 - Subscriber+ Subscription Cancellation via IDOR | |
| CVE-2026-11883 | WebAuthn Provider for Two Factor < 2.5.6 - 2FA Bypass |
No comments yet