WordPress JSON Options 插件 0.0.4 版本在其某个动作中未进行任何权限检查(capability check)或非ces 验证(nonce verification),该动作在每个请求中都会执行,且对所有未认证用户开放。这使得未认证用户可以更新任意 WordPress 选项。攻击者可利用此漏洞启用用户注册功能,并将默认角色设置为管理员,从而引发权限提升,最终导致整个网站被接管。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | JSON Options | ≤ 0.0.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | JSON Options | 0 ~ 0.0.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74992 | Kirki < 6.2.3 - Editor+ Stored XSS via Font Zip Upload | |
| CVE-2026-19699 | GutenKit 2.4.12 - 2.4.15 - Contributor+ Mailchimp Audience Data Disclosure | |
| CVE-2026-19615 | Admin and Site Enhancements < 9.0.1 - Author+ Stored XSS via SVG Upload over XML-RPC | |
| CVE-2026-19697 | GutenKit < 2.5.0 - Author+ Stored XSS via SVG Upload | |
| CVE-2026-15049 | Depicter < 4.8.0 - Editor+ Arbitrary File Upload via ZIP Import | |
| CVE-2026-13405 | Royal Elementor Addons < 1.7.1066 - Admin+ Remote Code Execution via Widget Builder |
No comments yet