以下是这段漏洞描述的中文翻译: MW WP Form WordPress 插件在 5.1.6 版本之前,在将部分表单设置输出到后台管理页面时,未对其进行净化和转义,这可能导致权限低至“编辑者”(Editor)角色的用户,针对管理员等高权限用户执行存储型跨站脚本(Stored XSS)攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | MW WP Form | 0 ~ 5.1.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81660 | Groundhogg < 4.5.13 - Unauthenticated Stored XSS via Web Form Dropdown/Radio Field | |
| CVE-2026-81766 | Really Simple Security < 9.8.0 - Multisite Subsite Admin+ Arbitrary Plugin Installation vi | |
| CVE-2026-19722 | WPvivid Backup & Migration < 0.9.133 - Admin+ Arbitrary File Write via Zip Slip in Backup | |
| CVE-2026-76585 | Customer Reviews for WooCommerce < 5.118.0 - Unauthenticated Stored XSS via 'comment' Para | |
| CVE-2026-14835 | SOGO Add Script to Individual Pages Header Footer <= 3.9 - Contributor+ Stored XSS via Pos | |
| CVE-2026-14307 | Geotargeting WP < 3.5.6.2 - Reflected XSS |
No comments yet