在 GutenKit WordPress 插件 2.5.0 之前的版本中,其部分 REST API 端点缺乏足够的权限检查,导致具有“投稿者”(Contributor)及以上角色的用户能够从网站连接的营销账户中检索邮件列表受众的元数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75860 | JSON Options <= 0.0.4 - Unauthenticated Arbitrary Options Update | |
| CVE-2026-74992 | Kirki < 6.2.3 - Editor+ Stored XSS via Font Zip Upload | |
| CVE-2026-19615 | Admin and Site Enhancements < 9.0.1 - Author+ Stored XSS via SVG Upload over XML-RPC | |
| CVE-2026-19697 | GutenKit < 2.5.0 - Author+ Stored XSS via SVG Upload | |
| CVE-2026-15049 | Depicter < 4.8.0 - Editor+ Arbitrary File Upload via ZIP Import | |
| CVE-2026-13405 | Royal Elementor Addons < 1.7.1066 - Admin+ Remote Code Execution via Widget Builder |
No comments yet