Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WPC Admin Columns | 0 ~ 2.3.4 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14925 | Import WP < 2.14.23 - Unauthenticated Sensitive Information Exposure via Export File Downl | |
| CVE-2026-16294 | Blubrry PowerPress < 11.17.1 - Contributor+ Server-Side Request Forgery via Podcast Episod | |
| CVE-2026-16253 | Total Upkeep (BoldGrid Backup) < 1.17.3 - Unauthenticated Sensitive Data Disclosure and Fo | |
| CVE-2026-16066 | Welcart e-Commerce < 2.11.34 - Author+ Stored XSS via Product Name | |
| CVE-2026-16538 | TeraWallet - Wallet for WooCommerce < 1.6.10 - Subscriber+ Wallet Balance Inflation via Di | |
| CVE-2026-15388 | Cookie Consent < 0.0.10 - Subscriber+ Consent Settings Update and Consent Log Disclosure | |
| CVE-2026-15039 | Gift Cards For WooCommerce Pro < 4.2.10 - Unauthenticated Arbitrary File Upload | |
| CVE-2026-15249 | Patterns Kit <= 1.0.3 - Contributor+ Stored XSS via YouTube Popup Link | |
| CVE-2026-14857 | WP Crowdfunding < 2.2.1 - Subscriber+ Campaign Update Modification via IDOR | |
| CVE-2026-16051 | WPMU DEV Dashboard < 5.0.1 - Remote Code Execution via Hub Install Action | |
| CVE-2026-14858 | WP Crowdfunding < 2.2.1 - Subscriber+ Order Data Disclosure via IDOR | |
| CVE-2026-14859 | WP Crowdfunding < 2.2.1 - Subscriber+ Campaign Creation via Missing Authorization | |
| CVE-2026-13613 | KiviCare < 4.5.2 - Doctor/Receptionist+ SQL Injection via settings/listing REST Endpoint | |
| CVE-2026-12976 | LearnPress < 4.4.4 - Subscriber+ Sensitive Information Exposure via AI Assistant | |
| CVE-2026-13177 | Eventin < 4.1.20 - Contributor+ Order Information Disclosure via IDOR | |
| CVE-2026-13612 | KiviCare < 4.5.2 - Patient+ Cross-Patient Bill, Invoice and Appointment Disclosure via IDO | |
| CVE-2026-13168 | Eventin < 4.1.20 - Contributor+ Customer PII Disclosure via REST API | |
| CVE-2026-13171 | Eventin < 4.1.20 - Unauthenticated Account Creation via Waiting List Endpoint | |
| CVE-2026-18230 | WP Directory Kit < 1.5.6 - Subscriber+ SQL Injection via section Parameter | |
| CVE-2026-19073 | Order Sync with Zendesk for WooCommerce < 2.2.3 - Unauthenticated Customer Order Data Disc |
Showing top 20 of 37 CVEs. View all on vendor page → →
No comments yet