WordPress 插件 Content Mask 1.8.5.5 及之前版本在创建帖子类型时未检查发布该帖子类型所需的权限,导致权限级别低至“贡献者”(Contributor)的用户,即使不具备发布权限,也能在网站上发布文章和页面。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Content Mask | 1.8.0< 1.8.5.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Content Mask | 1.8.0 ~ 1.8.5.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77115 | Brave Popup Builder < 0.8.6 - Unauthenticated Reflected XSS via UTM Parameters | |
| CVE-2026-77116 | Brave Popup Builder < 0.8.6 - Subscriber+ Unpublished Popup Disclosure via Preview | |
| CVE-2026-14853 | WooCommerce Bookings < 3.9.0 - Subscriber+ Draft Bookable Product Creation via Missing Aut | |
| CVE-2026-13598 | RestrictMate < 1.3.0 - Unauthenticated Privilege Escalation to Administrator |
No comments yet