WordPress Product Input Fields for WooCommerce是WordPress基金会的一款产品输入字段插件。 WordPress Product Input Fields for WooCommerce 2.0.2之前版本存在安全漏洞,该漏洞源于未验证上传的文件类型,可能导致未经身份验证的攻击者上传任意文件并在不遵守目录访问规则的服务器上实现远程代码执行。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Product Input Fields for WooCommerce | 2.0.0< 2.0.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Product Input Fields for WooCommerce | 2.0.0 ~ 2.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14211 | Amelia Pro < 9.7 - Provider+ Arbitrary Customer Data Disclosure and Modification via IDOR | |
| CVE-2026-17022 | Salon Booking System – Free Version < 10.30.34 - Unauthenticated Booking Information Discl | |
| CVE-2026-15047 | s2Member < 260805 - Contributor+ Stored XSS via Shortcode | |
| CVE-2026-14238 | Vitepos < 3.6.0 - Admin+ SQL Injection via product-details-report | |
| CVE-2026-14293 | Autopay / Blue Media for WooCommerce < 5.0.1 - Unauthenticated Stored XSS via CSS Editor | |
| CVE-2026-19075 | All-in-One Video Gallery < 4.9.2 - Subscriber+ Server-Side Request Forgery via 'vdl' Param | |
| CVE-2026-19074 | Advanced Classifieds & Directory Pro < 3.4.3 - Unauthenticated Non-Public Listing Custom F | |
| CVE-2026-19077 | Copy & Delete Posts < 1.5.5 - Authenticated Arbitrary Post Deletion via Missing Object-Lev | |
| CVE-2026-14237 | Vitepos < 3.6.0 - Outlet Manager+ Privilege Escalation | |
| CVE-2026-17020 | Salon Booking System – Free Version <= 10.31.0 - Subscriber+ Arbitrary Booking PII Disclos | |
| CVE-2026-17021 | Salon Booking System – Free Version < 10.30.34 - Unauthenticated Arbitrary Booking Total T | |
| CVE-2026-19053 | ProSolution WP Client < 2.0.6 - Unauthenticated Blind SQLi via 'jobID' Parameter | |
| CVE-2026-19049 | ProSolution WP Client < 2.0.9 - Unauthenticated SQLi and Plugin Data Deletion via 'removes | |
| CVE-2026-18960 | Block User Account < 2.0.1 - Subscriber+ Account Block Bypass via Application Passwords | |
| CVE-2026-18946 | Contact Form to Any API < 3.0.7 - Unauthenticated Sensitive File Disclosure via Predictabl | |
| CVE-2026-18934 | RSS Aggregator by Feedzy < 5.2.6 - Author+ Cross-User Import Job Manipulation and Post Del | |
| CVE-2026-15229 | Pinpoint Booking System <= 2.9.9.7.1 - Unauthenticated Arbitrary Booking Price Manipulatio | |
| CVE-2026-16949 | Term Pages < 2.0.0 - Unauthenticated SQL Injection via tp_lookup | |
| CVE-2026-16985 | Squeeze < 1.7.12 - Author+ Arbitrary File Upload | |
| CVE-2026-15237 | Hotel Booking Lite < 6.2.3 - Unauthenticated Payment Record Creation via Checkout Payments |
Showing top 20 of 48 CVEs. View all on vendor page → →
No comments yet