WordPress WP Data Access是WordPress基金会的一款内容管理系统的数据管理插件。 WordPress WP Data Access 5.5.79之前版本存在信息泄露漏洞,该漏洞源于未验证其接受的列名且nonce未覆盖该操作,可能导致未经身份验证的攻击者读取数据库表的任意列,包括用户密码哈希。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | WP Data Access | < 5.5.79 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WP Data Access | 0 ~ 5.5.79 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15038 | InfiniteWP Client < 1.13.6 - Unauthenticated Administrator Account Takeover on Multisite | |
| CVE-2026-16032 | LWS Optimize < 4.1.2 - Unauthenticated Stored XSS via Real User Monitoring | |
| CVE-2026-18473 | WP Directory Kit < 1.5.5 - Unauthenticated SQL Injection via 'field_search' Parameter | |
| CVE-2026-18603 | Cancel Order & Request Woocommerce < 1.3.4.34 - Unauthenticated Order Content Disclosure v | |
| CVE-2026-18465 | WP Maps Pro < 6.1.3 - Unauthenticated Local File Inclusion | |
| CVE-2026-17017 | CubeWP Framework < 1.1.31 - Subscriber+ SQL Injection via cubewp_remove_relation | |
| CVE-2026-18357 | WPC Order Tip for WooCommerce < 3.3.1 - Unauthenticated Order Data Disclosure | |
| CVE-2026-18464 | WP Maps Pro < 6.1.3 - Unauthenticated Denial of Service | |
| CVE-2026-18037 | Create by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publicati | |
| CVE-2026-17044 | WordPress File Upload < 5.1.8 - Unauthenticated SQL Injection via uniqueuploadid | |
| CVE-2026-17014 | WP Photo Album Plus < 9.2.07.002 - Unauthenticated Export ZIP File Deletion via delexportz | |
| CVE-2026-16965 | Solace Extra < 1.6.1 - Subscriber+ Post Meta Update via solace_update_sitebuilder_status | |
| CVE-2026-16988 | GeoDirectory < 2.8.169 - Unauthenticated Pending/Draft Listing Disclosure via markers REST | |
| CVE-2026-16992 | Create by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publicati | |
| CVE-2026-16957 | Slim SEO < 4.9.11 - Contributor+ Arbitrary Post Meta Disclosure | |
| CVE-2026-17011 | Nexter Blocks < 5.0.2 - Contributor+ Stored CSS Injection |
No comments yet