WordPress Contact Form 7是WordPress基金会的一款WordPress表单插件动态文本扩展工具。 WordPress Contact Form 7 2.5之前版本存在输入验证错误漏洞,该漏洞源于未验证用户提供的返回URL的主机,可能导致未经身份验证的攻击者通过特制链接将受害者重定向到任意外部站点。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Contact Form 7 | < 2.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Contact Form 7 | 0 ~ 2.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14190 | Sina Extension for Elementor < 3.10.2 - Reflected XSS | |
| CVE-2026-14820 | Quiz And Survey Master < 11.1.3 - Unauthenticated User Enumeration and Password Oracle via | |
| CVE-2026-14827 | Calendar < 1.3.18 - Contributor+ Stored XSS via event_link Parameter | |
| CVE-2026-9830 | BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering v | |
| CVE-2026-14203 | Smart Manager < 8.92.0 - Contributor+ Stored XSS via Post Title | |
| CVE-2026-14568 | WP User Frontend < 4.3.8 - Unauthenticated Author-less Attachment Deletion | |
| CVE-2026-14289 | WP FacturaONE < 5.37 - Unauthenticated Remote Code Execution | |
| CVE-2026-14235 | WordPress Download Manager < 3.3.62 - Unauthorized Protected File Download via Reusable Do | |
| CVE-2026-13597 | QRcode Login for WeChat <= 1.3 - Unauthenticated Account Takeover | |
| CVE-2026-13726 | Multiple Page Generator Plugin – MPG < 4.1.8 - Reflected XSS via mpg_shortcode | |
| CVE-2026-13714 | Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upl | |
| CVE-2026-10082 | Advanced Ads – Ad Manager & AdSense < 2.0.23 - Contributor+ Stored XSS via the_ad Shortcod | |
| CVE-2026-14189 | WPBot AI ChatBot < 8.5.2 - Admin+ Second-Order SQL Injection via qc_bot_str_fields | |
| CVE-2026-13400 | Simply Schedule Appointments < 1.6.12.4 - Unauthenticated Stored XSS via Booking Customer | |
| CVE-2026-13332 | Masteriyo LMS < 2.3.1 - Unauthenticated Arbitrary User Session Termination (Denial of Serv | |
| CVE-2026-13390 | The Events Calendar < 6.16.5.1 - Unauthenticated Event Aggregator Import Status Manipulati | |
| CVE-2026-13152 | Custom Fields Account Registration For WooCommerce < 1.4 - Unauthenticated Privilege Escal | |
| CVE-2026-12982 | Document Gallery < 5.1.1 - Reflected XSS via dg_generate_gallery | |
| CVE-2026-12255 | MainWP Child < 6.1.2 - Unauthenticated Administrator Authentication Bypass via Passwordles | |
| CVE-2026-12394 | MemberGlut < 1.1.5 - Unauthenticated Privilege Escalation to Administrator |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet