SureCart WordPress 插件在 4.6.3 版本之前,未能确保受客户更新影响的账户与权限检查所授权的账户一致。这使得拥有“订阅者”权限级别账户的用户可以更改其他用户(包括管理员)的电子邮件地址,并通过密码重置功能接管该账户。此外,攻击者可以控制客户记录并将其与任意用户关联,同时向任何已认证用户泄露客户标识符和电子邮件地址。这些漏洞组合在一起,使得仅凭一个订阅者级别的账户即可实现账户接管。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85038 | B2BKing < 5.2.40 - Unauthenticated B2B Group Assignment and Approval Bypass via Registrati | |
| CVE-2026-84219 | Kirki 6.2.1 - 6.2.5 - Unauthenticated Stored XSS via HTML Entity Decoding | |
| CVE-2026-75793 | SureCart < 4.7.0 - Unauthenticated Account Creation with Automatic Login | |
| CVE-2026-84028 | Bold Page Builder < 5.9.9 - Contributor+ Stored XSS via Slider Elements' additional_settin | |
| CVE-2026-13159 | Real Estate Papi <= 1.0.5 - Subscriber+ Plugin Installation |
No comments yet