在 WP Maps WordPress 插件 4.9.7 版本之前,其某个 AJAX 操作未执行权限检查,且未对其分派的操作进行限制,导致拥有订阅者(Subscriber)角色的用户能够触发不受控制的递归行为,从而耗尽服务器资源,造成拒绝服务(Denial of Service)漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15211 | 5.9 MEDIUM | Subscriptions for WooCommerce < 2.0.1 - Payment Bypass via Attacker-Supplied PayPal Captur |
| CVE-2026-15148 | 5.3 MEDIUM | WP Events Manager < 2.2.5 - Unauthenticated Payment Bypass and Booking Status Update via I |
| CVE-2026-15239 | 5.3 MEDIUM | Simple CAPTCHA with Cloudflare Turnstile < 1.42.0 - Unauthenticated Turnstile Protection B |
| CVE-2026-14205 | WP Events Manager < 2.2.5 - Subscriber+ Payment Bypass via 'qty' Parameter | |
| CVE-2026-14943 | Password Protected < 2.8.4 - Unauthenticated Sensitive Information Exposure via REST API | |
| CVE-2026-14331 | Subscribe2 < 10.46 - Reflected XSS via email Parameter | |
| CVE-2026-15032 | wpDiscuz < 7.6.60 - Unauthenticated Stored XSS via Image URL Conversion | |
| CVE-2026-15215 | Subscriptions for WooCommerce < 2.0.1 - Shop Manager+ Arbitrary Plugin Installation | |
| CVE-2026-15214 | Subscriptions for WooCommerce < 2.0.1 - Subscriber+ Subscription Detail Disclosure via IDO | |
| CVE-2026-15359 | Templately < 3.7.1 - Unauthenticated Administrator Templately Cloud Connection Overwrite | |
| CVE-2026-15245 | BNE Testimonials < 2.0.8.2 - Contributor+ Stored XSS via Slider Shortcode | |
| CVE-2026-16030 | MStore API < 4.21.0 - Unauthenticated Account Takeover via Firebase Phone Authentication | |
| CVE-2026-16039 | MStore API < 4.21.0 - Subscriber+ Order and Customer PII Disclosure via IDOR | |
| CVE-2026-16038 | MStore API < 4.21.0 - Unauthenticated Payment Bypass via Multiple Payment Gateways | |
| CVE-2026-15361 | Content Views < 4.5 - Subscriber+ SQL Injection via preview_request | |
| CVE-2026-15386 | Meow Gallery < 5.5.2 - Author+ Stored XSS via Attachment Alt-Text | |
| CVE-2026-16262 | Estatik < 4.3.3 - Login CSRF | |
| CVE-2026-16041 | MStore API < 4.21.0 - Unauthenticated Product Review Creation | |
| CVE-2026-16263 | WP Maps < 4.9.7 - Subscriber+ Local File Inclusion | |
| CVE-2026-16258 | Ajax Search Lite < 4.14.5 - Unauthenticated PHP Object Injection via Search Statistics RES |
No comments yet