properfraction Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content是properfraction个人开发者的一款集会员管理、电子商务、用户注册登录、个人资料及内容限制功能的WordPress插件。 WordPress ProfilePress 4.16.18之前版本存在权限许可和访问控制问题漏洞,该漏洞源于角色限制执行不一致且缺少随机数检查
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content | < 4.16.18 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content | 0 ~ 4.16.18 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14603 | WowOptin < 1.4.38 - Unauthenticated Opt-in Deactivation and Template Row Injection | |
| CVE-2026-12688 | ProfileGrid < 5.9.9.7 - Unauthenticated Payment Bypass and Forced Group Membership via Pay | |
| CVE-2026-12689 | ProfileGrid < 5.9.9.7 - Subscriber+ Cross-User Private Message Thread Deletion and Tamperi | |
| CVE-2026-12690 | ProfileGrid < 5.9.9.7 - Subscriber+ Premium License Tampering via Missing Authorization | |
| CVE-2026-12981 | CAFEHAUS API <= 1.0.0 - Unauthenticated Arbitrary User Password Reset | |
| CVE-2026-12877 | Software Issue Manager < 5.1.0 - Unauthenticated SQL Injection via Search Parameter |
No comments yet