WordPress Advanced Form Integration是WordPress基金会的一款连接表单与超200个应用的集成插件。 WordPress Advanced Form Integration 2.1.1之前版本存在权限许可和访问控制问题漏洞,该漏洞源于未限制从公共表单提交创建用户时分配的WordPress角色,可能导致未经验证的访问者在活跃集成将用户角色映射到公共表单字段时创建管理员账户。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Advanced Form Integration — Connect Forms to 200+ Apps | < 2.1.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Advanced Form Integration — Connect Forms to 200+ Apps | 0 ~ 2.1.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11568 | Product Configurator for WooCommerce < 1.7.3 - Unauthenticated Private/Draft Product Data | |
| CVE-2026-11562 | WS Form LITE < 1.11.8 - Subscriber+ Arbitrary Settings Update | |
| CVE-2026-11570 | User Submitted Posts < 20260608 - Unauthenticated Stored XSS via Author Name | |
| CVE-2026-10750 | Royal MCP < 1.4.26 - Subscriber+ Insufficient Authorization in MCP Tools | |
| CVE-2026-11887 | Salon Booking System < 10.30.20 - Subscriber+ Booking Approval Bypass | |
| CVE-2026-11880 | Fluent Forms < 6.2.1 - Subscriber+ Subscription Cancellation via IDOR | |
| CVE-2026-11883 | WebAuthn Provider for Two Factor < 2.5.6 - 2FA Bypass |
No comments yet