WordPress MLSImport是WordPress基金会开源的一款导入房地产列表数据的CMS插件。 WordPress MLSImport 7.0.4之前版本存在安全漏洞,该漏洞源于其AJAX操作缺乏授权和CSRF检查,可能导致任何已认证用户(如订阅者)读取导入日志文件以及任意帖子的导入相关元数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings | < 7.0.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings | 0 ~ 7.0.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-16968 | GeoDirectory < 2.8.168 - Contributor+ User Email Disclosure via geodir_json_search_users | |
| CVE-2026-16036 | miniOrange 2FA < 6.2.7 - 2FA Bypass via Password-Only Second-Factor Rebinding | |
| CVE-2026-16055 | Contest Gallery < 30.0.7 - Unauthenticated Login-Protection and 2FA Bypass via post_cg_log | |
| CVE-2025-15677 | GeoDirectory < 2.8.110 - Editor+ Stored XSS via Place Categories | |
| CVE-2026-14553 | Zportals < 6.3.4 - Subscriber+ Arbitrary File Upload | |
| CVE-2026-15210 | Login/Signup with Phone Number, OTP Verification < 1.8.71 - Unauthenticated Account Takeov | |
| CVE-2026-15230 | YayPricing < 3.5.7 - Subscriber+ Pricing Configuration Modification and Coupon Code Disclo | |
| CVE-2026-15372 | WP 2FA < 4.1.0 - Two-Factor Authentication Bypass via Passkeys Provider | |
| CVE-2026-15360 | Ajax Load More < 8.0.1 - Unauthenticated SQL Injection via custom_args | |
| CVE-2026-16940 | Custom Fields for WooCommerce < 1.5.1 - Unauthenticated Arbitrary File Deletion via Path T | |
| CVE-2026-16981 | DHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Download via IDOR | |
| CVE-2026-16993 | DHL for WooCommerce < 4.0.1 - Unauthenticated Shipping Label Disclosure via Unprotected Up | |
| CVE-2026-16561 | Sunshine Photo Cart < 3.6.12 - Unauthenticated Private Gallery Comment Disclosure | |
| CVE-2026-16942 | WP Custom HTML Pages <= 0.6.2 - Author+ Stored XSS | |
| CVE-2026-16603 | Content Protector (Passster) < 4.3.6 - Unauthenticated Category-Locked Content Disclosure | |
| CVE-2026-16736 | User Registration & Membership < 5.2.6 - Unauthenticated Account Creation While Registrati | |
| CVE-2026-16613 | GDPR Cookie Compliance < 5.1.0 - Cookie Deletion and Forced Logout via CSRF | |
| CVE-2026-16604 | Content Protector (Passster) < 4.3.6 - Unauthenticated Protected Content Disclosure via Co | |
| CVE-2026-16746 | MultiVendorX < 5.0.11 - Store Owner+ Cross-Store Commission Data Disclosure via commission | |
| CVE-2026-16605 | MultiVendorX < 5.0.11 - Store Owner+ Cross-Vendor Store Takeover and Deletion via Missing |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet