WordPress 插件 Horizontal scrolling announcements 在 2.6 及更早版本中,未对其某项公告设置进行适当的清理和转义,便将其输出到前端页面的属性上下文中。这一缺陷使得拥有公告管理页面访问权限的用户(贡献者及以上权限,且需在启用相应权限后)能够实施存储型跨站脚本攻击(Stored XSS),当任何用户在前端查看该公告时,恶意脚本将在其浏览器中执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Horizontal scrolling announcements | 0 ~ 2.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93549 | CoCart 4.9.0 - 4.9.6 - Administrator Account Creation via REST API Authentication Bypass | |
| CVE-2026-97332 | User Private Files < 2.2.0 - Unauthenticated Private File Disclosure via .htaccess Rewrite | |
| CVE-2026-86817 | Five Star Business Profile and Schema 2.3.20 - 2.3.21 - Author+ Sensitive Data Disclosure | |
| CVE-2026-104118 | Razorpay for WooCommerce < 4.8.8 - Unauthenticated Order Shipping Modification via IDOR | |
| CVE-2026-104119 | Simple Shopping Cart < 5.2.6 - Admin+ Stored XSS via PayPal API Credentials |
No comments yet