GenieWords WordPress 插件(版本 1.5.27 至 1.5.34)在其部分 REST API 和 AJAX 操作中缺少授权检查,并且在输出前对存储值进行解码,这使得未认证的用户能够覆盖该插件的配置,并注入任意 Web 脚本,这些脚本将在每个前端页面上执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | GenieWords | 1.5.27 ~ 1.5.34 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81648 | 10.0 CRITICAL | CryptoPayment Gateway 1.2.1 - 1.2.2 - Unauthenticated Arbitrary File Deletion and Settings |
| CVE-2026-85129 | 8.8 HIGH | Hoo Companion 1.0.2 - Unauthenticated Stored XSS via Theme Settings Import |
| CVE-2026-88793 | 8.8 HIGH | YouTube Embed 10.0 - 10.3 - Unauthenticated Stored XSS via youram_server |
| CVE-2026-88802 | 7.5 HIGH | MDJM Event Management and Mobile Events Manager - Unauthenticated Arbitrary Post Deletion |
| CVE-2026-89050 | 4.3 MEDIUM | Quads Ads Manager for Google AdSense < 3.0.5 - Subscriber+ Ad-Selling Payment Bypass via U |
| CVE-2026-77773 | Social Contact Form (FormyChat) < 2.15.8 - Unauthenticated Gravity Forms Entry Disclosure | |
| CVE-2026-86406 | User Registration & Membership < 5.2.8 - Subscriber+ Privilege Escalation via Membership P | |
| CVE-2026-80071 | User Registration & Membership < 5.2.8 - Author+ Privilege Escalation to Administrator | |
| CVE-2026-80072 | User Registration & Membership < 5.2.8 - Unauthenticated Open Redirect via Login Redirect | |
| CVE-2026-86407 | User Registration & Membership < 5.2.8 - Unauthenticated User Data Disclosure via Membersh | |
| CVE-2026-88764 | Simple Membership < 4.7.8 - Subscriber+ Membership Level Escalation via PayPal Standard su | |
| CVE-2026-88912 | rtMedia for WordPress, BuddyPress and bbPress < 4.7.12 - Subscriber+ Arbitrary Activity Pr | |
| CVE-2026-88995 | Bookit < 2.6.0.1 - Unauthenticated Appointment PII Disclosure via Availability Check | |
| CVE-2026-89080 | Really Simple Security < 9.8.1 - Unauthenticated 2FA Bypass via Email Provider State Demot |
No comments yet