Real Estate Papi WordPress 主题在 1.0.5 版本之前,对其中的一个 AJAX 操作未执行权限(capability)或 CSRF 检查,使得任何已认证的用户(例如订阅者 subscriber)都能从 WordPress.org 仓库安装一组固定的配套插件(plugins)。如果该请求在具有激活权限的用户会话中执行,这些插件也会被自动激活。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Real Estate Papi | 0 ~ 1.0.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85038 | B2BKing < 5.2.40 - Unauthenticated B2B Group Assignment and Approval Bypass via Registrati | |
| CVE-2026-84219 | Kirki 6.2.1 - 6.2.5 - Unauthenticated Stored XSS via HTML Entity Decoding | |
| CVE-2026-75793 | SureCart < 4.7.0 - Unauthenticated Account Creation with Automatic Login | |
| CVE-2026-18480 | SureCart < 4.6.3 - Subscriber+ Administrator Account Takeover | |
| CVE-2026-84028 | Bold Page Builder < 5.9.9 - Contributor+ Stored XSS via Slider Elements' additional_settin |
No comments yet