在 WP Directory Kit WordPress 插件 1.5.7 之前的版本中,插件在使用某个参数之前未对其进行适当的清理和转义,导致管理员可以执行 SQL 注入攻击。在 multisite(多站点)安装环境中,这使得单个站点的管理员能够读取整个网络中其他数据的内容,而这些数据通常是他们无法直接访问的。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | WP Directory Kit | < 1.5.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WP Directory Kit | 0 ~ 1.5.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-19726 | Visualizer < 4.0.7 - Contributor+ Cross-User Chart Configuration Disclosure | |
| CVE-2026-19728 | Extra Product Options Builder for WooCommerce < 1.2.176 - Unauthenticated Customer File Di | |
| CVE-2026-19725 | WPvivid Backup & Migration < 0.9.131 - Unauthenticated Path Traversal via send_to_site_con | |
| CVE-2026-19712 | Masteriyo LMS < 2.3.3 - Instructor+ Stored XSS via Quiz Description | |
| CVE-2026-19613 | ECS < 4.3.10 - Contributor+ Arbitrary Post Meta Disclosure via Dynamic Repeater ACF Source | |
| CVE-2026-19717 | CatFolders Document Gallery < 2.0.7 - Unauthenticated Attachment Disclosure via REST API | |
| CVE-2026-19714 | Simple JWT Login < 3.6.8 - Unauthenticated Account Takeover via Missing Google id_token Au | |
| CVE-2026-19711 | Premium Packages – Sell Digital Products Securely < 7.0.7 - Subscriber+ Arbitrary Amount W | |
| CVE-2026-15384 | Manual Image Crop < 1.15 - Subscriber+ Arbitrary Attachment Image Overwrite via IDOR | |
| CVE-2026-13712 | Divi 5.0 - 5.8.1 - Contributor+ Stored XSS via Social Media Follow Skype URL | |
| CVE-2026-17533 | All-in-One WP Migration and Backup < 7.108 - Multisite Subsite Admin+ Network-Wide PHP Cod |
No comments yet