WordPress 插件“临时登录(无密码)”在 1.9.9 版本之前,在授予新账户网络超级管理员权限时,未验证发起临时登录请求的用户是否确实拥有网络超级管理员权限,这使得多站点网络中单个站点的管理员可以接管整个网络。同样的缺失检查也允许提升现有账户(包括攻击者自己的账户)的权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Temporary Login Without Password | 1.5 ~ 1.9.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80494 | Yogeta WP Cloud <= 1.0 - Unauthenticated Arbitrary File Download | |
| CVE-2026-82845 | Masteriyo LMS < 3.4.1 - Subscriber+ PHP Object Injection | |
| CVE-2026-82847 | Masteriyo LMS < 3.4.1 - Instructor+ Stored XSS via Course Highlights | |
| CVE-2026-81742 | BE REST Endpoints <= 1.0.0 - Unauthenticated Stored XSS and Widget Manipulation | |
| CVE-2026-84023 | BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Taxonomy Te | |
| CVE-2026-81090 | Gpx2Graphics <= 0.3 - Arbitrary File Upload via CSRF | |
| CVE-2026-81429 | Export & Import WPBakery Page Builder <= 1.0.2 - Stored XSS via CSRF | |
| CVE-2026-81402 | DS Ad Rotator <= 0.8 - Unauthenticated Arbitrary File Upload | |
| CVE-2026-80491 | SAMO Forms <= 1.0.0 - Unauthenticated SQLi | |
| CVE-2026-82851 | Masteriyo LMS 1.14.0 - 3.4.0 - Instructor+ Arbitrary Post Disclosure via IDOR | |
| CVE-2026-77006 | WebTotem Backups <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path Traversal | |
| CVE-2026-77689 | Amelia Pro 9.0 - 9.8 - Unauthenticated Payment Bypass | |
| CVE-2026-77705 | Amelia < 2.4.10 - Amelia Manager+ WordPress Account Takeover | |
| CVE-2026-77753 | Temporary Login Without Password < 1.9.9 - Authenticated Temporary Access Revocation Bypas | |
| CVE-2026-78152 | SureRank 1.6.2 - 1.10.0 - Unauthenticated Author Email Disclosure via Person Schema | |
| CVE-2026-75800 | Frontegg SAML SSO <= 1.0.1 - Unauthenticated Account Takeover via Unverified SAMLResponse | |
| CVE-2026-77005 | Code Monkeys Proposals <= 1.0.1 - Subscriber+ Arbitrary File Deletion via Path Traversal | |
| CVE-2026-83532 | Custom Menu Wizard <= 3.3.1 - Contributor+ Stored XSS via Shortcode Attributes | |
| CVE-2026-87797 | Client Invoicing by Sprout Invoices < 20.8.16 - Subscriber+ Private Note Overwrite via si_ | |
| CVE-2026-87918 | WPBot < 8.5.7 - Unauthenticated AI Provider API Abuse via Multiple AJAX Actions |
Showing top 20 of 36 CVEs. View all on vendor page → →
No comments yet