WordPress FluentCart A New Era of eCommerce是WordPress基金会的一款电子商务平台。 WordPress FluentCart A New Era of eCommerce 1.4.0之前版本存在权限许可和访问控制问题漏洞,该漏洞源于未验证订阅是否属于请求客户,允许任何认证客户在知道目标订阅标识符时操作其他客户的订阅(更改支付方式、取消和重新绑定)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | FluentCart A New Era of eCommerce | < 1.4.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | FluentCart A New Era of eCommerce | 0 ~ 1.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14545 | TrueBooker Appointment Booking < 1.2.4 - Unauthenticated Account Takeover via Password Res | |
| CVE-2026-14924 | Tablesome < 1.1.31 - Unauthenticated Post Creation and Modification | |
| CVE-2026-14870 | Database for Contact Form 7, WPforms, Elementor forms < 1.5.3 - Reflected XSS via form_id | |
| CVE-2026-14821 | Quiz And Survey Master < 11.1.5 - Contributor+ Arbitrary Template Deletion | |
| CVE-2026-14819 | Event Tickets < 5.28.4 - Editor+ Stored XSS via Ticket Move |
No comments yet