jordymeow ai engine是jordymeow个人开发者开源的一款人工智能算法引擎。 WordPress AI Engine 3.5.5之前版本存在路径遍历漏洞,该漏洞源于未对用户提供的文件名进行清理,可能允许拥有编辑器级别访问权限的认证用户通过路径遍历将攻击者控制的字节写入服务器上的任意位置。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12583 | Newsletters < 4.15 - Unauthenticated PHP Object Injection via Subscriber Custom Field | |
| CVE-2026-12988 | WP 2FA < 3.1.1.2 - Account Takeover via 2FA Setup Email Binding | |
| CVE-2026-11563 | Word Count and Social Shares <= 1.0 - Subscriber+ Arbitrary File Deletion via Path Travers | |
| CVE-2026-11567 | SureForms < 2.11.1 - Unauthenticated Payment Amount Bypass | |
| CVE-2025-15665 | BEAF < 4.7.1 - Admin+ Stored XSS via Widget Shortcode Field |
No comments yet