在 Eventin WordPress 插件 4.1.19 版本之前,未正确限制访客结账令牌(guest checkout token)可以对订单进行哪些更改的授权,导致未经身份验证的用户可以将自己未支付的订单标记为已完成,并获得有效的已付费门票,而无需实际支付费用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-19226 | Royal Elementor Addons < 1.7.1066 - Contributor+ Stored XSS via Image Accordion Widget Eff | |
| CVE-2026-78146 | Noptin < 4.3.3 - Unauthenticated Subscriber PII and confirm_key Disclosure via Actions Pag | |
| CVE-2026-77790 | RegistrationMagic < 6.0.9.4 - Admin+ SQLi via 'rm_sortby' Parameter | |
| CVE-2026-77754 | Kirki < 6.0.14 - Unauthenticated User and Comment Author Email Disclosure via kirki_get_ap | |
| CVE-2026-77789 | Stripe Payment Forms by WP Full Pay < 8.5.1 - Cross-Customer Subscription Modification via | |
| CVE-2026-77758 | Stripe Payment Forms by WP Full Pay < 8.5.1 - Unauthenticated Customer Portal Subscription | |
| CVE-2026-77757 | Directorist 8.5 - 8.9.2 - Subscriber+ Arbitrary Image Move via REST v2 Listing Submission | |
| CVE-2026-77695 | Woo Refund And Exchange Lite < 4.6.4 - Unauthenticated Guest Order Message Disclosure and | |
| CVE-2026-74929 | WP Project Manager < 4.0.7 - Subscriber+ Cross-Project Task Disclosure and Task Board Modi | |
| CVE-2026-74930 | WP Project Manager 2.2.0 - 4.0.6 - Subscriber+ User Activity Feed Disclosure via IDOR | |
| CVE-2026-77693 | Order Tip for WooCommerce < 1.6.0 - Shop Manager+ Arbitrary File Deletion via delete_expor | |
| CVE-2026-75797 | AI Engine 3.3.3 - 3.7.1 - Subscriber+ Arbitrary File Read via 'url' Parameter | |
| CVE-2026-75798 | AI Engine 3.4.0 - 3.7.1 - Unauthenticated Arbitrary AI Query Execution via Editor Assistan | |
| CVE-2026-14212 | Amelia Pro < 9.8 - Provider+ Arbitrary Provider Password Update via IDOR | |
| CVE-2026-19220 | Forminator Forms < 1.57.1 - Unauthenticated Multisite Site Creation and Privilege Escalati | |
| CVE-2026-19718 | BlogVault, MalCare and WP Remote 5.16 - 6.62 - Unauthenticated Site Takeover via Connectio | |
| CVE-2026-74928 | WP Project Manager 2.1.0 - 4.0.6 - Unauthenticated Subscriber Account Creation via Trello | |
| CVE-2026-74851 | Pods < 3.3.9.1 - Author+ RCE via Shortcode Display Callback | |
| CVE-2026-14550 | WPCafe < 3.0.18 - Unauthenticated Reservation Approval Bypass via Missing Authorization | |
| CVE-2026-14216 | Amelia < 2.4.7 - Unauthenticated Notification Queue Dispatch |
Showing top 20 of 27 CVEs. View all on vendor page → →
No comments yet