Ninja Forms WordPress 插件(3.14.10 至 3.15.2 之前的版本)未阻止来自请求的短代码在执行时未被过滤,导致当它将这些短代码替换到后续会进行短代码处理的内容中时,未认证用户可以执行站点上注册的任何短代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Ninja Forms | 3.14.10< 3.15.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Ninja Forms | 3.14.10 ~ 3.15.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-19859 | 6.5 MEDIUM | JetFormBuilder < 3.6.5.2 - Unauthenticated Arbitrary Shortcode Execution via 'status' Para |
| CVE-2026-80439 | 4.8 MEDIUM | Redirection for Contact Form 7 2.2.7 - 3.2.10 - Unauthenticated Arbitrary Shortcode Execut |
| CVE-2026-19862 | 4.8 MEDIUM | JetFormBuilder < 3.6.5.2 - Unauthenticated Email Header Injection via Send Email Action |
| CVE-2026-85038 | B2BKing < 5.2.40 - Unauthenticated B2B Group Assignment and Approval Bypass via Registrati | |
| CVE-2026-84219 | Kirki 6.2.1 - 6.2.5 - Unauthenticated Stored XSS via HTML Entity Decoding | |
| CVE-2026-75793 | SureCart < 4.7.0 - Unauthenticated Account Creation with Automatic Login | |
| CVE-2026-18480 | SureCart < 4.6.3 - Subscriber+ Administrator Account Takeover | |
| CVE-2026-84028 | Bold Page Builder < 5.9.9 - Contributor+ Stored XSS via Slider Elements' additional_settin | |
| CVE-2026-13159 | Real Estate Papi <= 1.0.5 - Subscriber+ Plugin Installation |
No comments yet