WordPress InfiniteWP Client是WordPress基金会开源的一款远程管理客户端组件。 WordPress InfiniteWP Client 1.13.6之前版本存在授权问题漏洞,该漏洞源于未正确验证站点连接状态和请求真实性,可能导致未认证攻击者绑定自己的密钥、劫持管理员会话、接管整个网络,导致远程代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | InfiniteWP Client | < 1.13.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | InfiniteWP Client | 0 ~ 1.13.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-16032 | LWS Optimize < 4.1.2 - Unauthenticated Stored XSS via Real User Monitoring | |
| CVE-2026-18473 | WP Directory Kit < 1.5.5 - Unauthenticated SQL Injection via 'field_search' Parameter | |
| CVE-2026-18603 | Cancel Order & Request Woocommerce < 1.3.4.34 - Unauthenticated Order Content Disclosure v | |
| CVE-2026-18465 | WP Maps Pro < 6.1.3 - Unauthenticated Local File Inclusion | |
| CVE-2026-17017 | CubeWP Framework < 1.1.31 - Subscriber+ SQL Injection via cubewp_remove_relation | |
| CVE-2026-18357 | WPC Order Tip for WooCommerce < 3.3.1 - Unauthenticated Order Data Disclosure | |
| CVE-2026-18464 | WP Maps Pro < 6.1.3 - Unauthenticated Denial of Service | |
| CVE-2026-18037 | Create by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publicati | |
| CVE-2026-18032 | WP Data Access < 5.5.79 - Unauthenticated Sensitive Data Disclosure via Autocomplete Colum | |
| CVE-2026-17044 | WordPress File Upload < 5.1.8 - Unauthenticated SQL Injection via uniqueuploadid | |
| CVE-2026-17014 | WP Photo Album Plus < 9.2.07.002 - Unauthenticated Export ZIP File Deletion via delexportz | |
| CVE-2026-16965 | Solace Extra < 1.6.1 - Subscriber+ Post Meta Update via solace_update_sitebuilder_status | |
| CVE-2026-16988 | GeoDirectory < 2.8.169 - Unauthenticated Pending/Draft Listing Disclosure via markers REST | |
| CVE-2026-16992 | Create by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publicati | |
| CVE-2026-16957 | Slim SEO < 4.9.11 - Contributor+ Arbitrary Post Meta Disclosure | |
| CVE-2026-17011 | Nexter Blocks < 5.0.2 - Contributor+ Stored CSS Injection |
No comments yet