LitExtension WordPress 插件 1.2.5 版本中,在执行覆盖商店迁移连接器认证令牌的后台管理操作前,未验证非ce(nonce)值,导致攻击者可以通过构造恶意链接欺骗已登录的管理员点击,从而劫持该连接器的认证令牌(CSRF 攻击)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | LitExtension | ≤ 1.2.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | LitExtension | 0 ~ 1.2.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-19848 | 6.5 MEDIUM | ProfilePress < 4.17.1 - Unauthenticated Arbitrary Shortcode Execution via Display Name |
| CVE-2026-17559 | 5.3 MEDIUM | Content Protector (Passster) < 4.3.9 - Unauthenticated Protected Content Disclosure via RE |
| CVE-2026-16650 | 5.3 MEDIUM | Charitable < 1.8.12 - Unauthenticated Donation Payment-Status Manipulation via Square Webh |
| CVE-2026-15150 | 5.3 MEDIUM | myCred < 3.2.5 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verificati |
| CVE-2026-18356 | 3.7 LOW | Limit Login Attempts Reloaded < 3.3.5 - Username Denylist Bypass via Case Variant and Acco |
| CVE-2026-13176 | 2.7 LOW | Eventin < 4.1.21 - Contributor+ Server-Side Request Forgery |
| CVE-2026-13736 | NewPath WildApricotPress Add-on – Member Directory <= 1.0.0 - Unauthenticated Member PII D | |
| CVE-2025-15671 | Welcart e-Commerce < 2.12.1 - Session Fixation via uscesid Parameter | |
| CVE-2026-14325 | Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Admin+ Stored XSS via dr | |
| CVE-2026-14601 | Link Whisper < 0.9.7 - Editor+ SQL Injection via domain Parameter | |
| CVE-2026-16576 | Dokan < 5.0.14 - Shop Manager+ Arbitrary Plugin Installation/Activation via REST API | |
| CVE-2026-16962 | Tamara Checkout <= 1.9.9.20 - Unauthenticated Order Status Manipulation | |
| CVE-2026-16575 | Dokan < 5.0.14 - Unauthenticated Commission Settings Disclosure via Store Categories REST | |
| CVE-2026-19085 | Copy & Delete Posts < 1.5.6 - Author+ Password-Protected Post Content Disclosure | |
| CVE-2026-19435 | Copy & Delete Posts < 1.5.6 - Authenticated Arbitrary Post Content and Password Disclosure | |
| CVE-2026-18781 | Drag and Drop Multiple File Upload for Contact Form 7 < 1.3.9.9 - Unauthenticated RCE via | |
| CVE-2026-16959 | Media Library Assistant < 3.40 - Author+ SQL Injection via mla_search_connector | |
| CVE-2026-16577 | Dokan < 5.0.14 - Vendor+ Reverse Withdrawal Ledger Manipulation via Client-Supplied Amount | |
| CVE-2026-75796 | AI Engine 2.8.0 - 3.6.0 - Admin+ Multisite Network Administrator Account Takeover via MCP |
No comments yet