在 Backup Migration WordPress 插件版本低于 2.1.7 的版本中,存在一个恢复后自动登录机制未能正确限制的问题。这使得一名管理多站点网络中某个站点的用户,可以在不提供凭证的情况下,绕过双因素认证,获得作为该网络中另一站点管理员的长期认证会话。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Backup Migration | < 2.1.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Backup Migration | 0 ~ 2.1.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14230 | ECS < 4.3.8 - Contributor+ Stored XSS via Dynamic Repeater Bindings | |
| CVE-2026-14229 | ECS < 4.3.8 - Unauthenticated Private Content Disclosure via ecsload | |
| CVE-2026-16541 | Simply Schedule Appointments < 1.6.12.17 - Team Member+ User Email Disclosure via Users an | |
| CVE-2026-16611 | Product Feed PRO for WooCommerce < 13.5.7 - Unauthenticated Feed Configuration Disclosure | |
| CVE-2026-18807 | ECS < 4.3.8 - Contributor+ Arbitrary Post Binding and Global Preset Modification via Dynam |
No comments yet