WordPress WPC Order Tip for WooCommerce是WordPress基金会开源的一款为在线商店添加订单小费功能的插件。 WordPress WPC Order Tip for WooCommerce存在信息泄露漏洞,攻击者利用该漏洞获取属于该商店任意客户的敏感订单数据,例如账单姓名、订单 ID 及状态、费用金额和订单日期。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | WPC Order Tip for WooCommerce | < 3.3.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WPC Order Tip for WooCommerce | 0 ~ 3.3.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15038 | InfiniteWP Client < 1.13.6 - Unauthenticated Administrator Account Takeover on Multisite | |
| CVE-2026-16032 | LWS Optimize < 4.1.2 - Unauthenticated Stored XSS via Real User Monitoring | |
| CVE-2026-18473 | WP Directory Kit < 1.5.5 - Unauthenticated SQL Injection via 'field_search' Parameter | |
| CVE-2026-18603 | Cancel Order & Request Woocommerce < 1.3.4.34 - Unauthenticated Order Content Disclosure v | |
| CVE-2026-18465 | WP Maps Pro < 6.1.3 - Unauthenticated Local File Inclusion | |
| CVE-2026-17017 | CubeWP Framework < 1.1.31 - Subscriber+ SQL Injection via cubewp_remove_relation | |
| CVE-2026-18464 | WP Maps Pro < 6.1.3 - Unauthenticated Denial of Service | |
| CVE-2026-18037 | Create by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publicati | |
| CVE-2026-18032 | WP Data Access < 5.5.79 - Unauthenticated Sensitive Data Disclosure via Autocomplete Colum | |
| CVE-2026-17044 | WordPress File Upload < 5.1.8 - Unauthenticated SQL Injection via uniqueuploadid | |
| CVE-2026-17014 | WP Photo Album Plus < 9.2.07.002 - Unauthenticated Export ZIP File Deletion via delexportz | |
| CVE-2026-16965 | Solace Extra < 1.6.1 - Subscriber+ Post Meta Update via solace_update_sitebuilder_status | |
| CVE-2026-16988 | GeoDirectory < 2.8.169 - Unauthenticated Pending/Draft Listing Disclosure via markers REST | |
| CVE-2026-16992 | Create by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publicati | |
| CVE-2026-16957 | Slim SEO < 4.9.11 - Contributor+ Arbitrary Post Meta Disclosure | |
| CVE-2026-17011 | Nexter Blocks < 5.0.2 - Contributor+ Stored CSS Injection |
No comments yet