在版本低于 4.21.0 的 MStore API WordPress 插件中,其 REST 产品评论创建接口未进行授权或购买所有权验证,导致未认证的攻击者可以在那些配置为仅接受已验证所有者提交评论的商店中,创建包含攻击者自定义的评论者姓名、电子邮件地址和星级评分的 WooCommerce 产品评论。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | MStore API | < 4.21.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | MStore API | 0 ~ 4.21.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15211 | 5.9 MEDIUM | Subscriptions for WooCommerce < 2.0.1 - Payment Bypass via Attacker-Supplied PayPal Captur |
| CVE-2026-15148 | 5.3 MEDIUM | WP Events Manager < 2.2.5 - Unauthenticated Payment Bypass and Booking Status Update via I |
| CVE-2026-15239 | 5.3 MEDIUM | Simple CAPTCHA with Cloudflare Turnstile < 1.42.0 - Unauthenticated Turnstile Protection B |
| CVE-2026-14205 | WP Events Manager < 2.2.5 - Subscriber+ Payment Bypass via 'qty' Parameter | |
| CVE-2026-14943 | Password Protected < 2.8.4 - Unauthenticated Sensitive Information Exposure via REST API | |
| CVE-2026-14331 | Subscribe2 < 10.46 - Reflected XSS via email Parameter | |
| CVE-2026-15032 | wpDiscuz < 7.6.60 - Unauthenticated Stored XSS via Image URL Conversion | |
| CVE-2026-15215 | Subscriptions for WooCommerce < 2.0.1 - Shop Manager+ Arbitrary Plugin Installation | |
| CVE-2026-15214 | Subscriptions for WooCommerce < 2.0.1 - Subscriber+ Subscription Detail Disclosure via IDO | |
| CVE-2026-15359 | Templately < 3.7.1 - Unauthenticated Administrator Templately Cloud Connection Overwrite | |
| CVE-2026-15245 | BNE Testimonials < 2.0.8.2 - Contributor+ Stored XSS via Slider Shortcode | |
| CVE-2026-16030 | MStore API < 4.21.0 - Unauthenticated Account Takeover via Firebase Phone Authentication | |
| CVE-2026-16039 | MStore API < 4.21.0 - Subscriber+ Order and Customer PII Disclosure via IDOR | |
| CVE-2026-16038 | MStore API < 4.21.0 - Unauthenticated Payment Bypass via Multiple Payment Gateways | |
| CVE-2026-15361 | Content Views < 4.5 - Subscriber+ SQL Injection via preview_request | |
| CVE-2026-15386 | Meow Gallery < 5.5.2 - Author+ Stored XSS via Attachment Alt-Text | |
| CVE-2026-16262 | Estatik < 4.3.3 - Login CSRF | |
| CVE-2026-16263 | WP Maps < 4.9.7 - Subscriber+ Local File Inclusion | |
| CVE-2026-16265 | WP Maps < 4.9.7 - Subscriber+ Denial of Service | |
| CVE-2026-16258 | Ajax Search Lite < 4.14.5 - Unauthenticated PHP Object Injection via Search Statistics RES |
No comments yet