在 Elementor Essential Addons WordPress 插件(版本低于 6.7.2)中,未对用户提交的注册字段进行适当验证,导致攻击者可以利用用户可控的注册字段覆盖系统保留的账户属性。该漏洞允许未经身份验证的攻击者在已配置具有特定标签的自定义用户个人资料字段的网站上,注册具有任意角色(包括管理员)的账户。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Essential Addons for Elementor | 5.8.6< 6.7.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Essential Addons for Elementor | 5.8.6 ~ 6.7.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15205 | Paymob for WooCommerce < 4.1.9 - Unauthenticated SQL Injection via Paymob Callback Pixel L | |
| CVE-2026-16739 | Epeken All Kurir <= 2.1.4 - Unauthenticated Order Payment Confirmation Forgery | |
| CVE-2026-14290 | Embed Google Photos Album Easily <= 2.2.1 - Contributor+ Stored XSS via link Shortcode Att |
No comments yet