WPManageNinja Fluent Forms是WPManageNinja公司的一款Web组件构建工具。 WPManageNinja Fluent Forms 6.2.1之前版本存在授权问题漏洞,该漏洞源于在处理订阅取消请求前未正确验证所有权,可能导致低权限的已认证用户取消其他用户的订阅。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Fluent Forms | < 6.2.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Fluent Forms | 0 ~ 6.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11568 | Product Configurator for WooCommerce < 1.7.3 - Unauthenticated Private/Draft Product Data | |
| CVE-2026-11562 | WS Form LITE < 1.11.8 - Subscriber+ Arbitrary Settings Update | |
| CVE-2026-11570 | User Submitted Posts < 20260608 - Unauthenticated Stored XSS via Author Name | |
| CVE-2026-11794 | Advanced Form Integration < 2.1.1 - Unauthenticated Privilege Escalation via Breakdance Fo | |
| CVE-2026-10750 | Royal MCP < 1.4.26 - Subscriber+ Insufficient Authorization in MCP Tools | |
| CVE-2026-11887 | Salon Booking System < 10.30.20 - Subscriber+ Booking Approval Bypass | |
| CVE-2026-11883 | WebAuthn Provider for Two Factor < 2.5.6 - 2FA Bypass |
No comments yet