Liquid Web / StellarWP WPComplete 中存在跨站请求伪造(CSRF)漏洞,导致存储型跨站脚本(Stored XSS)攻击。该问题影响 WPComplete 插件:从初始版本到 2.9.5.6 版本均受此漏洞影响。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Liquid Web / StellarWP | WPComplete | 0 ~ 2.9.5.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-105890 | 6.5 MEDIUM | WordPress Gutenberg Blocks by Kadence Blocks plugin <= 3.7.12 - Cross Site Scripting (XSS) |
| CVE-2026-105888 | 5.4 MEDIUM | WordPress Event Tickets plugin <= 5.30.0.1 - Broken Access Control vulnerability |
| CVE-2026-106600 | 5.3 MEDIUM | WordPress GiveWP plugin <= 4.18.0 - Broken Access Control vulnerability |
| CVE-2026-105893 | 5.3 MEDIUM | WordPress Event Tickets plugin <= 5.30.0.1 - Broken Access Control vulnerability |
| CVE-2026-105891 | 4.3 MEDIUM | WordPress Event Tickets plugin <= 5.30.0.1 - Broken Access Control vulnerability |
No comments yet