Notiqoo WordPress 插件在 1.4.14 版本之前的版本中,部分 AJAX 操作缺少权限检查,且根据用户输入构建要写入的选项名称。这使得角色低至 contributor(贡献者)的用户可以修改任意 WordPress 选项,从而能够停用 1.4.14 之前的 Notiqoo 插件,甚至将所有管理员锁定在站点之外。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82925 | Site Reviews 7.2.2 - 8.2.2 - Unauthenticated PHP Object Injection via Form Signature | |
| CVE-2026-81431 | Registration Form for WooCommerce 1.1.0 - 1.1.2 - Contributor+ Privilege Escalation via Un | |
| CVE-2026-77770 | miniOrange 2FA (Free & Pro) - Unauthenticated Arbitrary Option Deletion via Out-of-Band Em | |
| CVE-2026-77771 | miniOrange 2FA (Free & Pro) - 2FA Bypass via Session-Scoped OTP Lockout | |
| CVE-2026-78361 | zipMoney(Zip Co) Payments Plugin for WooCommerce < 2.4.0 - Unauthenticated Arbitrary Optio | |
| CVE-2026-19436 | Ultimate Gift Cards For WooCommerce < 3.2.10 - Unauthenticated Gift Card Value Inflation v | |
| CVE-2026-19439 | Ultimate Gift Cards for WooCommerce 3.0.3 - 3.2.9 - Unauthenticated Gift Card Code and Cus |
No comments yet