WordPress Theme Demo Import是WordPress基金会开源的一款快速导入主题演示内容的工具。 WordPress Theme Demo Import 1.1.3及之前版本存在任意文件上传漏洞,该漏洞源于未验证上传文件类型,可能导致高权限用户上传可执行PHP文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Theme Demo Import | ≤ 1.1.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Theme Demo Import | 0 ~ 1.1.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-13596 | Participants Database < 2.7.8.4 - Unauthenticated SQL Injection via List Search | |
| CVE-2025-15669 | Bit Form < 3.1.4 - Admin+ Stored XSS via Conversational Form Progress Label | |
| CVE-2026-12966 | Direct Payments for WooCommerce < 2.5.3 - Unauthenticated Cross-Customer Order Tampering v | |
| CVE-2026-15932 | Support Genix Lite < 1.4.48 - Unauthenticated Arbitrary File Read via Path Traversal | |
| CVE-2026-14309 | Chat On Desk < 1.0.9 - Unauthenticated Account Takeover via Password Reset OTP Bypass | |
| CVE-2026-14596 | DynamicKit for Elementor < 1.0.3 - Unauthenticated Account Takeover via Password Reset Lin | |
| CVE-2026-14836 | Login/Signup Popup < 3.2.5 - Unauthenticated Account Takeover via Password Reset Rate Limi | |
| CVE-2026-14197 | Fluent Support < 2.3.1 - Agent+ Arbitrary Ticket Customer Reassignment via IDOR | |
| CVE-2026-15244 | HUSKY - Products Filter Professional for WooCommerce < 1.4.1 - Shop Manager+ Local File In | |
| CVE-2026-15368 | Profile Builder < 3.16.4 - Unauthenticated Account Takeover via Auto-Login After Registrat | |
| CVE-2026-15234 | Codeless Page Builder <= 1.1.4 - Contributor+ Stored XSS via Shortcode Attribute | |
| CVE-2026-15262 | Admin Columns for ACF Fields <= 0.3.2 - Contributor+ Stored XSS via ACF Field Value Column | |
| CVE-2026-13158 | Everest Toolkit <= 1.2.3 - Admin+ Arbitrary File Upload | |
| CVE-2026-10827 | Spectra (Ultimate Addons for Gutenberg) < 2.20.0 - Contributor+ Stored CSS Injection via B | |
| CVE-2026-13604 | Pixelavo < 1.5.4 - Unauthenticated Facebook CAPI Event Injection via pixelavo_event AJAX | |
| CVE-2026-14840 | YOP Poll < 7.0.6 - Unauthenticated Vote Restriction Bypass via IP Header Spoofing | |
| CVE-2026-13329 | WC Buckaroo BPE Gateway < 4.9.0 - Subscriber+ Unauthorized Order Refund | |
| CVE-2026-12696 | wpForo Forum < 3.1.2 - Subscriber+ Stored XSS via Profile Location Field | |
| CVE-2026-11882 | Builderall for WordPress < 3.0.2 - Unauthenticated OAuth Access Token Poisoning via Public | |
| CVE-2026-13725 | Dynamic Pricing With Discount Rules for WooCommerce < 5.0.0 - Reflected XSS via wdpAjax |
Showing top 20 of 30 CVEs. View all on vendor page → →
No comments yet