WordPress Login & Register Forms是WordPress基金会的一款提供登录与注册表单功能的CMS插件。 WordPress Login & Register Forms 4.0.2之前版本存在安全漏洞,该漏洞源于密码重置验证状态未与被重置的账户或完成验证的一方绑定,而是依赖于客户端控制的值,可能导致未经身份验证的攻击者接管最近完成重置验证的任何用户(包括管理员)的账户。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Login & Register Forms | 3.2.5< 4.0.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Login & Register Forms | 3.2.5 ~ 4.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-17020 | Salon Booking System – Free Version <= 10.31.0 - Subscriber+ Arbitrary Booking PII Disclos | |
| CVE-2026-17023 | Salon Booking System – Free Version <= 10.30.33 - Unauthenticated Google Calendar Connecti | |
| CVE-2026-18786 | CheckView < 2.3.2 - Administrator Account Creation via REST API Authentication Bypass | |
| CVE-2026-14293 | Autopay / Blue Media for WooCommerce < 5.0.1 - Unauthenticated Stored XSS via CSS Editor | |
| CVE-2026-19075 | All-in-One Video Gallery < 4.9.2 - Subscriber+ Server-Side Request Forgery via 'vdl' Param | |
| CVE-2026-19074 | Advanced Classifieds & Directory Pro < 3.4.3 - Unauthenticated Non-Public Listing Custom F | |
| CVE-2026-19089 | Product Input Fields for WooCommerce < 2.0.2 - Unauthenticated Arbitrary File Upload | |
| CVE-2026-19077 | Copy & Delete Posts < 1.5.5 - Authenticated Arbitrary Post Deletion via Missing Object-Lev | |
| CVE-2026-14238 | Vitepos < 3.6.0 - Admin+ SQL Injection via product-details-report | |
| CVE-2026-17021 | Salon Booking System – Free Version < 10.30.34 - Unauthenticated Arbitrary Booking Total T | |
| CVE-2026-17022 | Salon Booking System – Free Version < 10.30.34 - Unauthenticated Booking Information Discl | |
| CVE-2026-14211 | Amelia Pro < 9.7 - Provider+ Arbitrary Customer Data Disclosure and Modification via IDOR | |
| CVE-2026-19053 | ProSolution WP Client < 2.0.6 - Unauthenticated Blind SQLi via 'jobID' Parameter | |
| CVE-2026-19049 | ProSolution WP Client < 2.0.9 - Unauthenticated SQLi and Plugin Data Deletion via 'removes | |
| CVE-2026-18960 | Block User Account < 2.0.1 - Subscriber+ Account Block Bypass via Application Passwords | |
| CVE-2026-18946 | Contact Form to Any API < 3.0.7 - Unauthenticated Sensitive File Disclosure via Predictabl | |
| CVE-2026-18934 | RSS Aggregator by Feedzy < 5.2.6 - Author+ Cross-User Import Job Manipulation and Post Del | |
| CVE-2026-15229 | Pinpoint Booking System <= 2.9.9.7.1 - Unauthenticated Arbitrary Booking Price Manipulatio | |
| CVE-2026-16949 | Term Pages < 2.0.0 - Unauthenticated SQL Injection via tp_lookup | |
| CVE-2026-16985 | Squeeze < 1.7.12 - Author+ Arbitrary File Upload |
Showing top 20 of 48 CVEs. View all on vendor page → →
No comments yet