MW WP Form WordPress 插件在 5.1.5 版本之前存在漏洞:该插件未阻止用户提交值中的短代码(shortcodes)在被合并到后续处理的“消息”中时被执行,这使得未认证的用户能够运行站点上已注册的任何短代码。 利用该漏洞的前提是:站点必须被配置为在提交后向访客回显所提交的值。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | MW WP Form | 0 ~ 5.1.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-74916 | 6.5 MEDIUM | WP Fastest Cache 0.8.7.7 - 1.5.0 - Unauthenticated Cache Poisoning via Unkeyed Tracking Pa |
| CVE-2026-13611 | 5.3 MEDIUM | KiviCare – Clinic & Patient Management System (EHR) < 4.5.5 - Unauthenticated Patient Data |
No comments yet