在 6.3.1 版本之前,miniOrange 2FA WordPress 插件在删除网站选项时,未对来自未认证请求输入(unauthenticated request input)的选项名称进行有效的交易验证。这使得任何访客都可以删除任意选项,从而可能导致所有管理员被锁定在仪表板之外,或导致站点上所有 miniOrange 2FA WordPress 插件(6.3.1 版本之前 / 19.3 版本之前)被停用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | miniOrange 2FA | 5.3.24 ~ 6.3.1 | - |
|
| Unknown | miniOrange 2FA | 18.0 ~ 19.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82925 | Site Reviews 7.2.2 - 8.2.2 - Unauthenticated PHP Object Injection via Form Signature | |
| CVE-2026-81431 | Registration Form for WooCommerce 1.1.0 - 1.1.2 - Contributor+ Privilege Escalation via Un | |
| CVE-2026-77771 | miniOrange 2FA (Free & Pro) - 2FA Bypass via Session-Scoped OTP Lockout | |
| CVE-2026-78361 | zipMoney(Zip Co) Payments Plugin for WooCommerce < 2.4.0 - Unauthenticated Arbitrary Optio | |
| CVE-2026-19840 | Notiqoo < 1.4.14 - Contributor+ Arbitrary Option Update via Multiple AJAX Actions | |
| CVE-2026-19436 | Ultimate Gift Cards For WooCommerce < 3.2.10 - Unauthenticated Gift Card Value Inflation v | |
| CVE-2026-19439 | Ultimate Gift Cards for WooCommerce 3.0.3 - 3.2.9 - Unauthenticated Gift Card Code and Cus |
No comments yet