WooCommerce 使用的 zipMoney(Zip Co)支付插件在 2.4.0 版本之前的版本中,其中一个前端请求处理程序未执行任何授权检查,且没有限制调用者可以提供的选项名称,这使得未认证用户能够删除任意 WordPress 选项。该漏洞可被利用以破坏网站和访问控制配置,停用已安装的 zipMoney(Zip Co)支付插件(2.4.0 之前的版本),并导致网站离线。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | zipMoney(Zip Co) Payments Plugin for WooCommerce | 0 ~ 2.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82925 | Site Reviews 7.2.2 - 8.2.2 - Unauthenticated PHP Object Injection via Form Signature | |
| CVE-2026-81431 | Registration Form for WooCommerce 1.1.0 - 1.1.2 - Contributor+ Privilege Escalation via Un | |
| CVE-2026-77770 | miniOrange 2FA (Free & Pro) - Unauthenticated Arbitrary Option Deletion via Out-of-Band Em | |
| CVE-2026-77771 | miniOrange 2FA (Free & Pro) - 2FA Bypass via Session-Scoped OTP Lockout | |
| CVE-2026-19840 | Notiqoo < 1.4.14 - Contributor+ Arbitrary Option Update via Multiple AJAX Actions | |
| CVE-2026-19436 | Ultimate Gift Cards For WooCommerce < 3.2.10 - Unauthenticated Gift Card Value Inflation v | |
| CVE-2026-19439 | Ultimate Gift Cards for WooCommerce 3.0.3 - 3.2.9 - Unauthenticated Gift Card Code and Cus |
No comments yet