WordPress WP Directory Kit是WordPress基金会开源的一款目录管理插件。 WordPress WP Directory Kit 1.5.5之前版本存在SQL注入漏洞,该漏洞源于未对参数进行充分清理和转义,可能导致未经身份验证的用户利用SQL注入。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | WP Directory Kit | 1.5.4< 1.5.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WP Directory Kit | 1.5.4 ~ 1.5.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15038 | InfiniteWP Client < 1.13.6 - Unauthenticated Administrator Account Takeover on Multisite | |
| CVE-2026-16032 | LWS Optimize < 4.1.2 - Unauthenticated Stored XSS via Real User Monitoring | |
| CVE-2026-18603 | Cancel Order & Request Woocommerce < 1.3.4.34 - Unauthenticated Order Content Disclosure v | |
| CVE-2026-18465 | WP Maps Pro < 6.1.3 - Unauthenticated Local File Inclusion | |
| CVE-2026-17017 | CubeWP Framework < 1.1.31 - Subscriber+ SQL Injection via cubewp_remove_relation | |
| CVE-2026-18357 | WPC Order Tip for WooCommerce < 3.3.1 - Unauthenticated Order Data Disclosure | |
| CVE-2026-18464 | WP Maps Pro < 6.1.3 - Unauthenticated Denial of Service | |
| CVE-2026-18037 | Create by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publicati | |
| CVE-2026-18032 | WP Data Access < 5.5.79 - Unauthenticated Sensitive Data Disclosure via Autocomplete Colum | |
| CVE-2026-17044 | WordPress File Upload < 5.1.8 - Unauthenticated SQL Injection via uniqueuploadid | |
| CVE-2026-17014 | WP Photo Album Plus < 9.2.07.002 - Unauthenticated Export ZIP File Deletion via delexportz | |
| CVE-2026-16965 | Solace Extra < 1.6.1 - Subscriber+ Post Meta Update via solace_update_sitebuilder_status | |
| CVE-2026-16988 | GeoDirectory < 2.8.169 - Unauthenticated Pending/Draft Listing Disclosure via markers REST | |
| CVE-2026-16992 | Create by Mediavine < 2.5.4 - Unauthenticated Unpublished Content Disclosure and Publicati | |
| CVE-2026-16957 | Slim SEO < 4.9.11 - Contributor+ Arbitrary Post Meta Disclosure | |
| CVE-2026-17011 | Nexter Blocks < 5.0.2 - Contributor+ Stored CSS Injection |
No comments yet