ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution 是适用于 WordPress 的一款插件,该插件存在权限提升漏洞。在 4.9.4 及以下版本中,由于 函数被注册到 WordPress 核心 操作钩子上,且缺乏插件自有的能力检查以及白名单过滤机制,导致攻击者提供的 WXR 导入文件中的任意 名称/值对被直接传递给 函数。这使得具有 Shop Manager 级别访问权限及以上的用户可以写入任意的 Word
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| roxnor | ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets | ≤ 4.9.4 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| roxnor | ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widgets | 0 ~ 4.9.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-76063 | 6.4 MEDIUM | FundEngine <= 1.8.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'wfp_fea |
| CVE-2026-18100 | 6.4 MEDIUM | MetForm <= 4.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'mf_form_i |
| CVE-2026-75930 | 4.3 MEDIUM | FundEngine <= 1.8.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post |
No comments yet