zportals WordPress 插件(版本低于 6.4.2)在一个 AJAX 操作中未执行任何能力(capability)检查或 nonce 验证,导致具有订阅者级别权限的用户可以泄露所有已注册用户(包括管理员)的显示名称和电子邮件地址。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86601 | 6.5 MEDIUM | WP Recipe Maker < 10.8.2 - Unauthenticated Arbitrary Shortcode Execution via Comment Conte |
| CVE-2026-86612 | 5.6 MEDIUM | Ninja Tables < 5.2.17 - Unauthenticated Arbitrary Shortcode Execution via Fluent Forms Dat |
| CVE-2026-84091 | 5.3 MEDIUM | SUMIT Payment Gateway for WooCommerce < 4.0.0 - Unauthenticated Payment Confirmation Forge |
| CVE-2026-90950 | 5.3 MEDIUM | Paid Member Subscriptions < 3.1.0 - Unauthenticated reCAPTCHA Bypass via Registration Form |
| CVE-2026-87978 | 5.3 MEDIUM | Paymob for WooCommerce < 4.1.14 - Unauthenticated Payment Bypass via Unverified Subscripti |
| CVE-2026-87071 | 5.3 MEDIUM | Forminator Forms < 1.57.2.1 - Unauthenticated Post Meta Injection on Submitted Posts |
| CVE-2026-87070 | 5.3 MEDIUM | Forminator Forms < 1.57.2.1 - Unauthenticated Poll Vote Limit Bypass via IP Spoofing |
| CVE-2026-86604 | 4.8 MEDIUM | GTranslate < 5.0.1 - Unauthenticated Arbitrary Shortcode Execution via Email Translation |
| CVE-2026-87848 | 3.7 LOW | MPCX Lightbox 1.2.2 - 1.2.5 - Unauthenticated Non-Public Post Content Disclosure |
| CVE-2026-93511 | Premium Packages < 7.2.1 - Unauthenticated PayPal Webhook Signature Verification Bypass | |
| CVE-2026-87069 | Forminator Forms < 1.57.2.1 - Subscriber+ Form Stripe Field Migration via migrate_stripe | |
| CVE-2026-90985 | WPC Smart Compare for WooCommerce < 6.6.1 - Unauthenticated Password-Protected Product Des | |
| CVE-2026-91024 | Booking Manager < 2.1.21 - Author+ SQLi via ICS Import Feed UID (sync_gid) | |
| CVE-2026-89331 | FluentBoards 1.95 - 2.0.15 - Unauthenticated Board Member Email Address Disclosure via Pub | |
| CVE-2026-88997 | JSM Show Post Metadata < 4.9.1 - Contributor+ Stored XSS via Custom Field Meta Key | |
| CVE-2026-87981 | Paymob for WooCommerce < 4.1.14 - Contributor+ Payment Gateway Configuration Deletion and | |
| CVE-2026-87074 | Forminator Forms < 1.57.2.1 - Unauthenticated Arbitrary Recipient Email Sending with Attac | |
| CVE-2026-87979 | Paymob for WooCommerce < 4.1.14 - Unauthenticated Saved Card Token Write to Any User via W | |
| CVE-2026-88929 | Sale Booster 7.0.0 - 7.5.1 - Unauthenticated Non-Public Product Disclosure | |
| CVE-2026-86842 | Real3D Flipbook Lite < 5.4 - Author+ Content Deletion and Stored XSS via Global Settings O |
Showing top 20 of 57 CVEs. View all on vendor page → →
No comments yet