| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | WP Crowdfunding | < 2.2.1 | affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WP Crowdfunding | 0 ~ 2.2.1 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-16747 | 6.5 MEDIUM | Kirki < 6.2.1 - Unauthenticated Arbitrary Shortcode Execution via Form Email Actions |
| CVE-2026-15045 | 6.5 MEDIUM | Wallet System for WooCommerce < 2.7.10 - Customer+ Checkout Price Manipulation via Unvalid |
| CVE-2026-17008 | 5.3 MEDIUM | Quick PayPal Payments <= 5.7.50 - Unauthenticated Payment Bypass via PayPal IPN |
| CVE-2026-16990 | 5.3 MEDIUM | Payment Button for PayPal <= 1.2.3.44 - Unauthenticated Payment Price Manipulation |
| CVE-2026-15213 | 5.3 MEDIUM | Welcart e-Commerce < 2.11.33 - Unauthenticated Payment Bypass via Forged Settlement Callba |
| CVE-2026-16621 | 5.3 MEDIUM | Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via Pay |
| CVE-2026-18044 | 3.7 LOW | Estatik Real Estate Plugin < 4.3.4 - Unauthenticated Arbitrary-Recipient Mail Relay via Si |
| CVE-2026-13613 | KiviCare < 4.5.2 - Doctor/Receptionist+ SQL Injection via settings/listing REST Endpoint | |
| CVE-2026-17013 | WP Photo Album Plus < 9.2.07.002 - Reflected XSS via lbstart | |
| CVE-2026-13177 | Eventin < 4.1.20 - Contributor+ Order Information Disclosure via IDOR | |
| CVE-2026-12976 | LearnPress < 4.4.4 - Subscriber+ Sensitive Information Exposure via AI Assistant | |
| CVE-2026-13612 | KiviCare < 4.5.2 - Patient+ Cross-Patient Bill, Invoice and Appointment Disclosure via IDO | |
| CVE-2026-15039 | Gift Cards For WooCommerce Pro < 4.2.10 - Unauthenticated Arbitrary File Upload | |
| CVE-2026-15388 | Cookie Consent < 0.0.10 - Subscriber+ Consent Settings Update and Consent Log Disclosure | |
| CVE-2026-16538 | TeraWallet - Wallet for WooCommerce < 1.6.10 - Subscriber+ Wallet Balance Inflation via Di | |
| CVE-2026-16066 | Welcart e-Commerce < 2.11.34 - Author+ Stored XSS via Product Name | |
| CVE-2026-16253 | Total Upkeep (BoldGrid Backup) < 1.17.3 - Unauthenticated Sensitive Data Disclosure and Fo | |
| CVE-2026-16294 | Blubrry PowerPress < 11.17.1 - Contributor+ Server-Side Request Forgery via Podcast Episod | |
| CVE-2026-16051 | WPMU DEV Dashboard < 5.0.1 - Remote Code Execution via Hub Install Action | |
| CVE-2026-13171 | Eventin < 4.1.20 - Unauthenticated Account Creation via Waiting List Endpoint |
Showing top 20 of 44 CVEs. View all on vendor page → →
No comments yet