4.17 及更早版本的 Newsletters WordPress 插件在保存其设置页面时,未执行任何 nonce 或权限(capability)检查,并将所有提交的参数写入其自身的选项设置中。这使得攻击者可以通过跨站请求伪造(CSRF)攻击,诱导已登录的管理员覆盖 Newsletters WordPress 插件(4.17 之前版本)的任意设置,包括保护其 API 的凭据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Newsletters | 0 ~ 4.17 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-76586 | BookingPress 1.5.6 - 1.6.2 - Unauthenticated Booking Price Manipulation via PayPal Payment | |
| CVE-2026-10522 | Simple User Registration <= 6.9 - Unauthenticated Privilege Escalation to Administrator | |
| CVE-2026-16061 | Rest Routes <= 5.5.5 - Unauthenticated SQLi via custom-tables/tables/{table_name} | |
| CVE-2026-16947 | Total Processing Card Payments for WooCommerce <= 7.3 - Unauthenticated SSRF leading to Pa | |
| CVE-2026-16600 | SmartAIPress <= 1.2.0 - Subscriber+ Server-Side Request Forgery via smartaipress_openai_up | |
| CVE-2026-16259 | Uix UserCenter <= 1.0.3 - Unauthenticated Privilege Escalation | |
| CVE-2026-17520 | Newsletters < 4.17 - Unauthenticated API Access via Predictable API Key | |
| CVE-2026-76546 | Profile Builder < 4.0.1 - Contributor+ Stored XSS via Format Date Shortcode | |
| CVE-2026-19430 | CatFolders Document Gallery Pro < 2.0.7 - Unauthenticated Missing Authorization via downlo | |
| CVE-2026-18234 | MStore API < 4.21.1 - Subscriber+ Arbitrary Order Payment Bypass via Wallet | |
| CVE-2026-18233 | MStore API < 4.21.1 - Subscriber+ Arbitrary Order Completion | |
| CVE-2026-76547 | Profile Builder < 4.0.1 - Admin+ PHP Object Injection via Import/Export | |
| CVE-2026-76548 | Profile Builder < 4.0.1 - Unauthenticated Unpublished Content and Media Modification via F | |
| CVE-2026-81026 | MasterStudy LMS < 3.7.40 - Unauthenticated Payment Bypass via PayPal IPN | |
| CVE-2026-77010 | HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated Moderator Jo | |
| CVE-2026-77012 | Icollect <= 1.0.0 - Unauthenticated Arbitrary File Read, SSRF and Path Traversal File Writ | |
| CVE-2026-77008 | HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated Plugin Setti | |
| CVE-2026-77007 | HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated BigBlueButto | |
| CVE-2026-80311 | Stripe Payment Forms by WP Full Pay < 8.5.5 - Cross-Customer Subscription Cancellation via | |
| CVE-2026-80488 | WP Ultimate CSV Importer < 9.0 - Admin+ SQLi via AIOSEO Import Fields |
Showing top 20 of 26 CVEs. View all on vendor page → →
No comments yet