以下是对该漏洞描述的中文翻译: Contact Form 7 重定向插件(版本 2.2.7 至 3.2.11 之前)存在一个漏洞:当该插件将用户提交的表单值代入动作(action)设置,并处理其中的短代码(shortcodes)时,未能阻止这些短代码被执行。这使得未认证用户能够执行网站上注册的任意短代码,并读取其输出结果。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Redirection for Contact Form 7 | 2.2.7< 3.2.11 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Redirection for Contact Form 7 | 2.2.7 ~ 3.2.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-19859 | 6.5 MEDIUM | JetFormBuilder < 3.6.5.2 - Unauthenticated Arbitrary Shortcode Execution via 'status' Para |
| CVE-2026-80437 | 4.8 MEDIUM | Ninja Forms 3.14.10 - 3.15.1 - Unauthenticated Arbitrary Shortcode Execution via IP and Re |
| CVE-2026-19862 | 4.8 MEDIUM | JetFormBuilder < 3.6.5.2 - Unauthenticated Email Header Injection via Send Email Action |
| CVE-2026-85038 | B2BKing < 5.2.40 - Unauthenticated B2B Group Assignment and Approval Bypass via Registrati | |
| CVE-2026-84219 | Kirki 6.2.1 - 6.2.5 - Unauthenticated Stored XSS via HTML Entity Decoding | |
| CVE-2026-75793 | SureCart < 4.7.0 - Unauthenticated Account Creation with Automatic Login | |
| CVE-2026-18480 | SureCart < 4.6.3 - Subscriber+ Administrator Account Takeover | |
| CVE-2026-84028 | Bold Page Builder < 5.9.9 - Contributor+ Stored XSS via Slider Elements' additional_settin | |
| CVE-2026-13159 | Real Estate Papi <= 1.0.5 - Subscriber+ Plugin Installation |
No comments yet