Nexcess The Events Calendar是Nexcess公司的一个事件日历管理插件。 WordPress The Events Calendar 6.16.5.1之前版本存在授权问题漏洞,该漏洞源于未对Event Aggregator导入REST API路由进行授权检查,并且跳过了特定状态值的完整性检查,导致未经身份验证的攻击者能够将现有导入记录标记为失败并在隐藏评论记录中存储任意内容。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | The Events Calendar | < 6.16.5.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | The Events Calendar | 0 ~ 6.16.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-13714 | Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upl | |
| CVE-2026-14820 | Quiz And Survey Master < 11.1.3 - Unauthenticated User Enumeration and Password Oracle via | |
| CVE-2026-14827 | Calendar < 1.3.18 - Contributor+ Stored XSS via event_link Parameter | |
| CVE-2026-9830 | BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering v | |
| CVE-2026-14203 | Smart Manager < 8.92.0 - Contributor+ Stored XSS via Post Title | |
| CVE-2026-14568 | WP User Frontend < 4.3.8 - Unauthenticated Author-less Attachment Deletion | |
| CVE-2026-14236 | Contact Form 7 – PayPal & Stripe Add-on < 2.5 - Open Redirect | |
| CVE-2026-14289 | WP FacturaONE < 5.37 - Unauthenticated Remote Code Execution | |
| CVE-2026-14235 | WordPress Download Manager < 3.3.62 - Unauthorized Protected File Download via Reusable Do | |
| CVE-2026-13597 | QRcode Login for WeChat <= 1.3 - Unauthenticated Account Takeover | |
| CVE-2026-13726 | Multiple Page Generator Plugin – MPG < 4.1.8 - Reflected XSS via mpg_shortcode | |
| CVE-2026-10082 | Advanced Ads – Ad Manager & AdSense < 2.0.23 - Contributor+ Stored XSS via the_ad Shortcod | |
| CVE-2026-14190 | Sina Extension for Elementor < 3.10.2 - Reflected XSS | |
| CVE-2026-14189 | WPBot AI ChatBot < 8.5.2 - Admin+ Second-Order SQL Injection via qc_bot_str_fields | |
| CVE-2026-13400 | Simply Schedule Appointments < 1.6.12.4 - Unauthenticated Stored XSS via Booking Customer | |
| CVE-2026-13332 | Masteriyo LMS < 2.3.1 - Unauthenticated Arbitrary User Session Termination (Denial of Serv | |
| CVE-2026-13152 | Custom Fields Account Registration For WooCommerce < 1.4 - Unauthenticated Privilege Escal | |
| CVE-2026-12982 | Document Gallery < 5.1.1 - Reflected XSS via dg_generate_gallery | |
| CVE-2026-12255 | MainWP Child < 6.1.2 - Unauthenticated Administrator Authentication Bypass via Passwordles | |
| CVE-2026-12394 | MemberGlut < 1.1.5 - Unauthenticated Privilege Escalation to Administrator |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet