Epeken All Kurir for WooCommerce WordPress 插件(版本直至 2.1.2)未验证支付确认请求是否确实来源于目标订单的所有者,也未验证是否实际发生了支付行为,从而导致未经身份验证的攻击者可以将任意订单标记为已确认,并且在非默认配置下,还可将订单标记为已支付。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Epeken All Kurir for Woocommerce | ≤ 2.1.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Epeken All Kurir for Woocommerce | 0 ~ 2.1.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15205 | Paymob for WooCommerce < 4.1.9 - Unauthenticated SQL Injection via Paymob Callback Pixel L | |
| CVE-2026-14290 | Embed Google Photos Album Easily <= 2.2.1 - Contributor+ Stored XSS via link Shortcode Att | |
| CVE-2026-18039 | Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom P |
No comments yet