WordPress 的 FundEngine – 捐赠与众筹平台插件存在存储型跨站脚本漏洞(Stored Cross-Site Scripting, XSS)。该漏洞影响 1.8.1 及更早版本,原因是插件对 参数缺乏足够的输入清理和输出转义处理。这使得已认证的攻击者(具备订阅者级别及以上权限)能够在页面中注入任意 Web 脚本,当其他用户访问被注入的页面时,这些脚本将自动执行。 用于提交视频 URL 的 REST 端点将其 设置为 ,这意味着任何已认证用户——包括仅拥有订阅者级别权限的用户——均可触发此漏洞代码路
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| roxnor | FundEngine – Donation and Crowdfunding Platform | ≤ 1.8.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| roxnor | FundEngine – Donation and Crowdfunding Platform | 0 ~ 1.8.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75971 | 7.2 HIGH | ShopEngine Elementor WooCommerce Builder Addon <= 4.9.4 - Authenticated (Shop Manager+) Pr |
| CVE-2026-18100 | 6.4 MEDIUM | MetForm <= 4.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'mf_form_i |
| CVE-2026-75930 | 4.3 MEDIUM | FundEngine <= 1.8.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Post |
No comments yet