WordPress WowOptin是WordPress基金会的一款CMS插件组件。 WordPress WowOptin 1.4.38之前版本存在权限许可和访问控制问题漏洞,该漏洞源于授权不当,允许未经身份验证的用户禁用所有选择加入表单并插入新的基于模板的选择加入行到数据库中。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | WowOptin: Next-Gen Popup Maker | < 1.4.38 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WowOptin: Next-Gen Popup Maker | 0 ~ 1.4.38 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-12688 | ProfileGrid < 5.9.9.7 - Unauthenticated Payment Bypass and Forced Group Membership via Pay | |
| CVE-2026-12689 | ProfileGrid < 5.9.9.7 - Subscriber+ Cross-User Private Message Thread Deletion and Tamperi | |
| CVE-2026-12690 | ProfileGrid < 5.9.9.7 - Subscriber+ Premium License Tampering via Missing Authorization | |
| CVE-2026-12981 | CAFEHAUS API <= 1.0.0 - Unauthenticated Arbitrary User Password Reset | |
| CVE-2026-12877 | Software Issue Manager < 5.1.0 - Unauthenticated SQL Injection via Search Parameter | |
| CVE-2026-12497 | ProfilePress < 4.16.18 - Unauthenticated Privilege Escalation via Registration Role Select |
No comments yet