WordPress Contest Gallery是WordPress基金会开源的一个管理竞赛作品的CMS组件。 WordPress Contest Gallery 30.0.7之前版本存在授权问题漏洞,该漏洞源于未对其一个处理程序执行任何权限或随机数检查,可能导致任何已认证用户(最低至订阅者)读取站点存储的完整OpenAI提示历史。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Contest Gallery | < 30.0.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Contest Gallery | 0 ~ 30.0.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-16035 | miniOrange 2FA < 6.2.7 - Subscriber+ Arbitrary-Recipient OTP Send | |
| CVE-2026-16618 | ImproveSEO <= 2.0.11 - Unauthenticated Arbitrary File Upload Leading to Remote Code Execut | |
| CVE-2026-10526 | EmbedPress < 4.6.1 - Unauthenticated Blind SSRF | |
| CVE-2026-11366 | MonsterInsights < 11.1.0 - Unauthenticated Measurement Protocol Secret Update via Empty-Ke | |
| CVE-2026-16536 | Simple Google Calendar Outlook Events Widget < 3.1.0 - Unauthenticated SSRF via calendar_i | |
| CVE-2026-16623 | Create Block Theme < 2.10.0 - Admin+ PHP Code Injection via Pattern Save (Multisite) | |
| CVE-2026-12698 | wpForo Forum < 3.1.3 - Subscriber+ Account Status and Reputation Manipulation via Profile | |
| CVE-2026-14939 | Visualizer: Tables and Charts Manager < 4.0.6 - Contributor+ Server-Side Request Forgery v | |
| CVE-2026-14816 | The GDPR Framework < 2.4.0 - Unauthenticated Consent Record Forgery and Do Not Sell Reques | |
| CVE-2026-14872 | Database for Contact Form 7, WPforms, Elementor forms < 1.5.5 - Authenticated SQL Injectio | |
| CVE-2026-14824 | Quiz And Survey Master < 11.2.2 - Contributor+ Stored XSS via Polar Question | |
| CVE-2026-14848 | Paid Member Subscriptions < 3.0.8 - Subscriber+ Cross-User Subscription Hijack via process | |
| CVE-2026-16296 | Clearfy < 2.4.3 - Open Redirect via Cyrlitera 404 Handler | |
| CVE-2026-15233 | Nested Pages < 3.2.15 - Editor+ Stored XSS via Post Title | |
| CVE-2026-15958 | Easy Dropbox Integration < 2.2.0 - Unauthenticated Arbitrary Connected Dropbox File Access | |
| CVE-2026-16293 | Blubrry PowerPress < 11.16.11 - Contributor+ Stored XSS via Podcast Episode Chapters URL | |
| CVE-2026-16068 | Brizy - Page Builder < 2.8.19 - Author+ Stored XSS via brizy_set_project Global Project Co | |
| CVE-2026-16069 | Brizy - Page Builder < 2.8.19 - Contributor+ Stored XSS via Featured Image Focal Point | |
| CVE-2026-16070 | Brizy - Page Builder < 2.8.19 - Contributor+ Template Type Update via IDOR | |
| CVE-2026-16548 | Bit Assist < 1.8.2 - Unauthenticated Arbitrary File Upload via Response Endpoint |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet