Timetics WordPress 插件(1.0.61 及之前版本)在通过 REST API 更新预约时,未强制执行“按对象所有权”机制,导致拥有该插件自定义“staff”(员工)角色的用户能够修改、禁用或接管其他员工名下的预约。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-4357 | 10.0 CRITICAL | Embed HTML5 Game <= 1.3 - Unauthenticated Arbitrary File Upload |
| CVE-2026-77009 | 9.9 CRITICAL | WatchMan-Site7 3.1.1 - 4.2.0 - Subscriber+ RCE via Debug Console |
| CVE-2025-9314 | 9.8 CRITICAL | Developer Tools <= 1.1.3 – Unauthenticated Arbitrary File Upload |
| CVE-2025-15485 | 8.2 HIGH | Auto x LINE <= 1.0.0 – Unauthenticated REST API Endpoints Call |
| CVE-2026-82884 | 6.8 MEDIUM | All in One SEO < 5.0.0.1 - Contributor+ Stored XSS via ai-assistant Block |
| CVE-2026-83547 | 6.8 MEDIUM | Xpro Elementor Addons 1.6.0 - 1.7.3 - Contributor+ Stored XSS via Multiple Widgets |
| CVE-2026-10821 | 6.6 MEDIUM | Yoast SEO Premium < 27.6.1 - Author+ Arbitrary .htaccess Directive Injection to RCE |
| CVE-2026-2688 | 6.5 MEDIUM | CM HIPAA Forms < 3.2.0 - Unauthenticated Authorization Bypass |
| CVE-2024-3773 | 5.9 MEDIUM | LiveJournal Shortcode <= 1.1.1 - Contributor+ Stored XSS via Shortcode |
| CVE-2026-2811 | 5.4 MEDIUM | Ajaxify Comments < 3.2 - Unauthenticated HTTP Header Injection |
| CVE-2026-8151 | 5.4 MEDIUM | Simple Membership MailChimp Integration < 1.9.8 - API Key Update via CSRF |
| CVE-2025-8945 | 5.3 MEDIUM | Wp Edit Password Protected < 1.3.5 - Protection Bypass via REST API |
| CVE-2026-17563 | 5.3 MEDIUM | WP User Frontend < 4.3.11 - Unauthenticated Post Creation via Subscription-Gated Form |
| CVE-2026-78153 | 5.3 MEDIUM | Restrict User Access 2.6 - 2.8 - Unauthenticated Content Protection Bypass via REST API Ro |
| CVE-2025-15490 | 5.3 MEDIUM | Passster < 4.2.26 - Global Protection Bypass |
| CVE-2026-77793 | 5.3 MEDIUM | RegistrationMagic < 6.0.9.9 - Unauthenticated Payment Bypass via Omitted Price Field |
| CVE-2026-77794 | 5.3 MEDIUM | RegistrationMagic 6.0.0.0 - 6.0.9.8 - Unauthenticated Payment Bypass via Zero Quantity |
| CVE-2025-15481 | 5.3 MEDIUM | Notification Bar for WordPress <= 1.1.8 – Unauthenticated Subscriber Data Disclosure |
| CVE-2026-83533 | 5.3 MEDIUM | WP Express Checkout < 2.4.9 - Unauthenticated Payment Bypass via wpec_process_payment |
| CVE-2025-15489 | 5.3 MEDIUM | Passster < 4.2.24 - Password Protection Bypass |
Showing top 20 of 66 CVEs. View all on vendor page → →
No comments yet