目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

CVE-2026-15230— YayPricing < 3.5.7 订阅配置修改与优惠券泄露

AI Predicted 6.5 Difficulty: Easy EPSS 0.14% · P4

Affected Version Matrix 1

ベンダープロダクトVersion Rangeステータス
UnknownYayPricing< 3.5.7affected
新しい脆弱性情報の通知を購読するログインして購読

I. CVE-2026-15230の基本情報

脆弱性情報

脆弱性についてご質問がありますか?Shenlongの分析が参考になるかご確認ください!
Shenlongの10の質問を表示 ↗

高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。

脆弱性タイトル
YayPricing < 3.5.7 - Subscriber+ Pricing Configuration Modification and Coupon Code Disclosure
ソース: CVE Program / CVE List V5
脆弱性説明
The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, allowing any authenticated user such as a subscriber to overwrite the store's pricing configuration and to disclose private coupon codes.
ソース: CVE Program / CVE List V5
CVSS情報
N/A
ソース: CVE Program / CVE List V5
脆弱性タイプ
N/A
ソース: CVE Program / CVE List V5

影響を受ける製品

ベンダープロダクト影響を受けるバージョンCPE購読
UnknownYayPricing 0 ~ 3.5.7 -

II. CVE-2026-15230の公開POC

#POC説明ソースリンクShenlongリンク
AI生成POCプレミアム

公開POCは見つかりませんでした。

ログインしてAI POCを生成

III. CVE-2026-15230のインテリジェンス情報

登录查看更多情报信息。

CVE-2026-15230 厂商安全公告 (1)

Same Patch Batch · Unknown · 2026-08-05 · 24 CVEs total

CVE-2026-16981DHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Download via IDOR
CVE-2026-16573Bit Form < 3.2.0 - Unauthenticated Stored XSS via SVG Signature Upload
CVE-2026-16602Content Protector (Passster) < 4.3.6 - Unauthenticated Non-Public Post Content Disclosure
CVE-2026-16583Orbit Fox by ThemeIsle < 3.0.8 - Author+ Stored XSS via SVG Upload
CVE-2026-16561Sunshine Photo Cart < 3.6.12 - Unauthenticated Private Gallery Comment Disclosure
CVE-2026-16603Content Protector (Passster) < 4.3.6 - Unauthenticated Category-Locked Content Disclosure
CVE-2026-16736User Registration & Membership < 5.2.6 - Unauthenticated Account Creation While Registrati
CVE-2026-16613GDPR Cookie Compliance < 5.1.0 - Cookie Deletion and Forced Logout via CSRF
CVE-2026-16604Content Protector (Passster) < 4.3.6 - Unauthenticated Protected Content Disclosure via Co
CVE-2026-16746MultiVendorX < 5.0.11 - Store Owner+ Cross-Store Commission Data Disclosure via commission
CVE-2026-16605MultiVendorX < 5.0.11 - Store Owner+ Cross-Vendor Store Takeover and Deletion via Missing
CVE-2026-16940Custom Fields for WooCommerce < 1.5.1 - Unauthenticated Arbitrary File Deletion via Path T
CVE-2026-16055Contest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_log
CVE-2026-16993DHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Disclosure via Unprotected Up
CVE-2026-16968GeoDirectory < 2.8.168 - Contributor+ User Email Disclosure via geodir_json_search_users
CVE-2026-16942WP Custom HTML Pages <= 0.6.2 - Author+ Stored XSS
CVE-2025-15677GeoDirectory < 2.8.110 - Editor+ Stored XSS via Place Categories
CVE-2026-14553Zportals < 6.3.4 - Subscriber+ Arbitrary File Upload
CVE-2026-15210Login/Signup with Phone Number, OTP Verification < 1.8.71 - Unauthenticated Account Takeov
CVE-2026-15372WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via Passkeys Provider

Showing 20 of 24 CVEs. View all on vendor page →

IV. 関連脆弱性

V. CVE-2026-15230へのコメント

まだコメントはありません


コメントを残す