WordPress LWS Optimize是WordPress基金会的一款网站性能优化工具。 WordPress LWS Optimize 4.1.2之前版本存在跨站脚本漏洞,该漏洞源于未正确转义通过未认证的分析端点提交的值,可能导致未经身份验证的攻击者注入任意Web脚本,当管理员查看受影响的仪表板页面时执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | LWS Optimize | < 4.1.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | LWS Optimize | 0 ~ 4.1.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15038 | InfiniteWP Client < 1.13.6 - Unauthenticated Administrator Account Takeover on Multisite | |
| CVE-2026-18473 | WP Directory Kit < 1.5.5 - Unauthenticated SQL Injection via 'field_search' Parameter | |
| CVE-2026-18603 | Cancel Order & Request Woocommerce < 1.3.4.34 - Unauthenticated Order Content Disclosure v | |
| CVE-2026-18465 | WP Maps Pro < 6.1.3 - Unauthenticated Local File Inclusion | |
| CVE-2026-17017 | CubeWP Framework < 1.1.31 - Subscriber+ SQL Injection via cubewp_remove_relation | |
| CVE-2026-18357 | WPC Order Tip for WooCommerce < 3.3.1 - Unauthenticated Order Data Disclosure | |
| CVE-2026-18464 | WP Maps Pro < 6.1.3 - Unauthenticated Denial of Service | |
| CVE-2026-18037 | Create by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publicati | |
| CVE-2026-18032 | WP Data Access < 5.5.79 - Unauthenticated Sensitive Data Disclosure via Autocomplete Colum | |
| CVE-2026-17044 | WordPress File Upload < 5.1.8 - Unauthenticated SQL Injection via uniqueuploadid | |
| CVE-2026-17014 | WP Photo Album Plus < 9.2.07.002 - Unauthenticated Export ZIP File Deletion via delexportz | |
| CVE-2026-16965 | Solace Extra < 1.6.1 - Subscriber+ Post Meta Update via solace_update_sitebuilder_status | |
| CVE-2026-16988 | GeoDirectory < 2.8.169 - Unauthenticated Pending/Draft Listing Disclosure via markers REST | |
| CVE-2026-16992 | Create by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publicati | |
| CVE-2026-16957 | Slim SEO < 4.9.11 - Contributor+ Arbitrary Post Meta Disclosure | |
| CVE-2026-17011 | Nexter Blocks < 5.0.2 - Contributor+ Stored CSS Injection |
No comments yet