melapress wp 2fa是melapress公司开源的一款双因素认证插件。 WordPress WP 2FA 3.1.1.2之前版本存在授权问题漏洞,该漏洞源于双因素身份验证设置期间未验证提供的电子邮件地址是否属于用户,可能导致获得用户凭据的攻击者将设置验证码重定向到攻击者控制的电子邮件地址并接管账户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12583 | Newsletters < 4.15 - Unauthenticated PHP Object Injection via Subscriber Custom Field | |
| CVE-2026-11563 | Word Count and Social Shares <= 1.0 - Subscriber+ Arbitrary File Deletion via Path Travers | |
| CVE-2026-11567 | SureForms < 2.11.1 - Unauthenticated Payment Amount Bypass | |
| CVE-2026-12511 | AI Engine < 3.5.5 - Editor+ Arbitrary File Write via Path Traversal | |
| CVE-2025-15665 | BEAF < 4.7.1 - Admin+ Stored XSS via Widget Shortcode Field |
No comments yet