WordPress Blog Floating Button是WordPress基金会开源的一款为博客添加悬浮按钮的组件。 WordPress Blog Floating Button 1.4.20及之前版本存在安全漏洞,该漏洞源于未清理或转义访问者的User-Agent标头,该标头通过未经身份验证的跟踪REST端点存储,并在管理员报告页面未转义渲染,可能导致未经身份验证的攻击者存储恶意脚本,在查看访问报告的管理员会话中执行,从而接管站点。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Blog Floating Button | ≤ 1.4.20 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Blog Floating Button | 0 ~ 1.4.20 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15231 | TaxoPress < 3.51.0 - Contributor+ Private Post Disclosure via IDOR | |
| CVE-2026-16057 | Contest Gallery < 30.0.7 - Author+ Arbitrary Post Deletion via post_cg_youtube_delete_from | |
| CVE-2026-16274 | Classified Listing < 5.4.4 - Contributor+ Unpublished Post Content Disclosure via rtcl_blo | |
| CVE-2026-15254 | Simply Schedule Appointments < 1.6.12.11 - Contributor+ Sensitive Data Disclosure via Admi | |
| CVE-2025-15672 | Chama < 1.0.13 - Unauthenticated PHP Object Injection | |
| CVE-2025-15673 | Import and export users and customers < 2.4.3 - Admin+ Arbitrary File Read | |
| CVE-2026-16532 | Link Library < 7.9.3 - Unauthenticated SQL Injection via the Front-End Link Submission For | |
| CVE-2026-16534 | Import and export users and customers < 2.4.2 - Custom Role Privilege Escalation to Admini | |
| CVE-2026-16276 | Classified Listing < 5.4.4 - Contributor+ Store Revenue Total Disclosure via rtcl_revenue_ | |
| CVE-2026-13340 | SVG Support < 2.5.17 - Author+ Stored XSS via .svgz Sanitization Bypass | |
| CVE-2026-12872 | Webinfos <= 1.2 - Unauthenticated Arbitrary File Upload | |
| CVE-2026-12965 | Super Store Finder < 7.11 - Unauthenticated SQL Injection via ssf_tracking | |
| CVE-2026-14557 | SoftMarket <= 1.0.0 - Unauthenticated Account Takeover via Email Verification Bypass | |
| CVE-2026-16565 | Dokan < 5.0.9 - Vendor+ Cross-Vendor Product Attribute Modification via Product Attribute | |
| CVE-2026-16060 | Insert or Embed Articulate Content into WordPress <= 4.3000000027 - Editor+ Arbitrary File | |
| CVE-2026-16250 | Personal QR Message <= 1.0 - Unauthenticated Arbitrary File Upload | |
| CVE-2026-15260 | Geo My WP < 4.5.5.3 - Subscriber+ Arbitrary Geolocation Record Modification and Deletion v | |
| CVE-2026-15931 | Simple Membership < 4.7.8 - Unauthenticated Stored XSS via PayPal Subscription Subscriber | |
| CVE-2026-15930 | Simple Membership < 4.7.8 - Unauthenticated Administrator Account Takeover via Registratio | |
| CVE-2026-16539 | SM Page Duplicator <= 1.0.0 - Editor+ SQL Injection via Page Duplication |
Showing top 20 of 27 CVEs. View all on vendor page → →
No comments yet