wpForo Forum WordPress 插件(3.0.0 至 3.1.6 版本)在使用客户端提供的 IP 地址标头来确定针对付费 AI 请求的每访客速率限制时,未对这些标头的来源进行验证。该缺陷允许未认证的攻击者通过伪造 IP 标头绕过速率限制,从而耗尽网站所有者的计量 AI 信用额度。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | wpForo Forum | 3.0.0 ~ 3.1.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86837 | 5.3 MEDIUM | Bookly < 28.3 - Unauthenticated Customer PII Update via Verification Bypass |
| CVE-2026-88848 | 4.2 MEDIUM | MasterStudy LMS 1.9 - < 3.7.50 - Subscriber+ Membership Plan Quota and Category Restrictio |
| CVE-2026-78394 | Link Library < 7.9.6 - Contributor+ Path Traversal via 'filepath' Parameter | |
| CVE-2026-78397 | Link Library < 7.9.6 - Unauthenticated SSRF via Reciprocal Link Validation | |
| CVE-2026-78393 | Link Library < 7.9.6 - Reflected XSS via 'link_tags' and 'link_price' Sort and Breadcrumb |
No comments yet