WordPress Streamit是WordPress基金会的一款CMS插件。 WordPress Streamit 4.5.0及之前版本存在代码注入漏洞,该漏洞源于未对AJAX路由进行授权或nonce验证,允许攻击者调用任意PHP函数,导致权限提升和远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-11351 | ShinyStat Analytics < 1.0.17 - Unauthenticated Non-Published Product Information Disclosur | |
| CVE-2026-11974 | Media folder Addon < 4.1.7 - Unauthenticated Arbitrary File Download | |
| CVE-2026-13605 | Photo Swipe <= 4.1.1.1 - Author+ Stored XSS via title Attribute | |
| CVE-2026-14234 | WOLF - WordPress Posts Bulk Editor and Manager < 1.1.0 - Stored XSS via CSRF | |
| CVE-2026-14224 | Easy Appointments < 3.12.28 - Subscriber+ Cross-User Appointment Data Modification via IDO | |
| CVE-2026-14300 | miniOrange Social Login and Register < 7.8.0 - Unauthenticated Account Takeover | |
| CVE-2026-13690 | UsersWP < 1.2.67 - Two-Factor Authentication Bypass | |
| CVE-2026-13692 | PayU CommercePro < 3.9.0 - Unauthenticated Order Tampering |
No comments yet