GutenKit WordPress 插件在 2.5.0 版本之前,未能对其启用的所有上传路径中的 SVG 文件进行适当的安全净化处理。这导致拥有文件上传权限(如作者角色)的用户可以上传恶意的 SVG 文件,从而对任何打开该文件的用户(包括管理员)实施存储型跨站脚本攻击(Stored XSS)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75860 | JSON Options <= 0.0.4 - Unauthenticated Arbitrary Options Update | |
| CVE-2026-74992 | Kirki < 6.2.3 - Editor+ Stored XSS via Font Zip Upload | |
| CVE-2026-19699 | GutenKit 2.4.12 - 2.4.15 - Contributor+ Mailchimp Audience Data Disclosure | |
| CVE-2026-19615 | Admin and Site Enhancements < 9.0.1 - Author+ Stored XSS via SVG Upload over XML-RPC | |
| CVE-2026-15049 | Depicter < 4.8.0 - Editor+ Arbitrary File Upload via ZIP Import | |
| CVE-2026-13405 | Royal Elementor Addons < 1.7.1066 - Admin+ Remote Code Execution via Widget Builder |
No comments yet