WordPress FunnelKit是WordPress基金会的一款面向WordPress平台的内容管理系统组件。 WordPress FunnelKit 3.15.0.6之前版本存在跨站脚本漏洞,该漏洞源于未对用户提供的参数进行转义处理直接反射到HTML响应中,可能导致未经身份验证的攻击者对登录用户执行反射型跨站脚本攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12907 | RTMKit Addons for Elementor < 2.0.9 - Author+ Site-Wide Theme Builder Template Creation an | |
| CVE-2026-12979 | FunnelKit < 3.15.0.6 - Admin+ Arbitrary File Deletion via Path Traversal in Template Impor | |
| CVE-2026-12869 | Header Footer Builder for Elementor < 1.2.1 - Contributor+ Stored XSS via Template Import | |
| CVE-2026-12525 | Redux Framework < 4.5.13 - Subscriber+ Privilege Escalation to Administrator | |
| CVE-2026-12906 | RTMKit Addons for Elementor < 2.0.9 - Contributor+ Private Post Title Disclosure | |
| CVE-2026-12510 | AI Engine < 3.5.5 - Subscriber+Chatbot Discussion Disclosure and Takeover via IDOR | |
| CVE-2026-12585 | Abandoned Cart Lite for WooCommerce < 6.8.2 - Unauthenticated Account Takeover via Malleab | |
| CVE-2026-12684 | Customer Reviews for WooCommerce < 5.113.0 - Unauthenticated Arbitrary Media Upload via cr | |
| CVE-2026-11866 | LatePoint < 5.6.3 - Multiple Privileged Actions via CSRF | |
| CVE-2026-11371 | BetterDocs < 4.5.5 - Unauthenticated Stored XSS via AI Doc Summarizer Prompt Injection | |
| CVE-2026-12492 | Happy Coders OTP Login for WooCommerce < 2.8 - Unauthenticated Account Takeover via hcotp_ | |
| CVE-2026-12395 | WP Job Portal < 2.5.5 - Subscriber+ SQL Injection via Applied Resumes 'ta' Parameter |
No comments yet