WP Import Export Lite WordPress 插件在 3.9.33 版本之前,在导入过程中请求 URL 前未进行充分校验,导致拥有“import”权限的用户(该权限默认由管理员持有)可以令站点向内部主机和服务发起请求,并读取其响应。这是对 CVE-2026-11397 的不完整修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | WP Import Export Lite | < 3.9.33 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WP Import Export Lite | 0 ~ 3.9.33 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-13407 | 6.1 MEDIUM | Royal Elementor Addons < 1.7.1067 - Unauthenticated Stored HTML Injection in Form Notifica |
| CVE-2026-84906 | 5.3 MEDIUM | Eventin < 4.1.24 - Unauthenticated Payment Bypass via Stripe and PayPal Cross-Order Transa |
| CVE-2026-86475 | 5.3 MEDIUM | Appointment Hour Booking < 1.5.95 - Unauthenticated Booking Capacity Bypass via Multi-Appo |
| CVE-2026-19857 | 4.8 MEDIUM | Formidable Forms < 6.35 - Unauthenticated Arbitrary Shortcode Execution via [entry_key] Cu |
| CVE-2026-76552 | WP Import Export Lite < 3.9.33 - Authenticated Arbitrary File Upload via Remote Image Impo | |
| CVE-2026-85349 | FluentBoards < 2.0.15 - Subscriber+ Private Board Membership Disclosure via IDOR | |
| CVE-2026-76555 | WP Import Export Lite < 3.9.33 - Authenticated Sensitive File Disclosure via Existing File | |
| CVE-2026-76557 | WP Import Export Lite < 3.9.33 - Authenticated SQLi via Import Options | |
| CVE-2026-76551 | WP Import Export Lite < 3.9.33 - Authenticated RCE via Export Field PHP Function | |
| CVE-2026-74926 | MultiVendorX 5.0.0 - 5.0.15 - Subscriber+ Arbitrary Store Data and Ownership Overwrite via | |
| CVE-2026-76553 | WP Import Export Lite < 3.9.33 - Authenticated Arbitrary Directory Deletion via Template P | |
| CVE-2026-82124 | Schema & Structured Data for WP & AMP < 1.66 - Unauthenticated Password-Protected Post Con | |
| CVE-2026-77702 | Eventin < 4.1.24 - Unauthenticated Ticket Price Rewrite via order_token | |
| CVE-2026-84829 | Optimole < 4.2.12 - Unauthenticated Stored XSS via Srcset Descriptor Parameter | |
| CVE-2026-84905 | Eventin < 4.1.24 - Contributor+ User Creation via Speaker Creation | |
| CVE-2026-84088 | Xpro Elementor Addons < 1.7.9 - Contributor+ Stored XSS via Interactive Circle Widget | |
| CVE-2026-82126 | Schema & Structured Data for WP & AMP 1.63 - 1.65 - Contributor+ Non-Public Post Content D | |
| CVE-2026-82125 | Schema & Structured Data for WP & AMP 1.46 - 1.65 - Unauthenticated Non-Public Comment Con | |
| CVE-2026-84907 | Eventin < 4.1.24 - Unauthenticated Order and Attendee Status Reset via Payment REST Endpoi | |
| CVE-2026-76550 | WP Import Export Lite < 3.9.34 - Authenticated RCE via Export Template Path Traversal |
Showing top 20 of 46 CVEs. View all on vendor page → →
No comments yet