WC Vendors WordPress 插件在 2.7.2.1 版本之前,在保存产品变体(product variations)时未验证用户提供的 ID 的所有权或对象类型,导致拥有供应商(vendor)角色的已认证用户能够修改属于其他供应商的产品变体,并能够修改任意文章(posts)的状态和标题,从而产生 IDOR(不安全的直接对象引用)漏洞。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | WC Vendors | < 2.7.2.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WC Vendors | 0 ~ 2.7.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-4357 | 10.0 CRITICAL | Embed HTML5 Game <= 1.3 - Unauthenticated Arbitrary File Upload |
| CVE-2026-77009 | 9.9 CRITICAL | WatchMan-Site7 3.1.1 - 4.2.0 - Subscriber+ RCE via Debug Console |
| CVE-2025-9314 | 9.8 CRITICAL | Developer Tools <= 1.1.3 – Unauthenticated Arbitrary File Upload |
| CVE-2025-15485 | 8.2 HIGH | Auto x LINE <= 1.0.0 – Unauthenticated REST API Endpoints Call |
| CVE-2026-83547 | 6.8 MEDIUM | Xpro Elementor Addons 1.6.0 - 1.7.3 - Contributor+ Stored XSS via Multiple Widgets |
| CVE-2026-82884 | 6.8 MEDIUM | All in One SEO < 5.0.0.1 - Contributor+ Stored XSS via ai-assistant Block |
| CVE-2026-10821 | 6.6 MEDIUM | Yoast SEO Premium < 27.6.1 - Author+ Arbitrary .htaccess Directive Injection to RCE |
| CVE-2026-2688 | 6.5 MEDIUM | CM HIPAA Forms < 3.2.0 - Unauthenticated Authorization Bypass |
| CVE-2024-3773 | 5.9 MEDIUM | LiveJournal Shortcode <= 1.1.1 - Contributor+ Stored XSS via Shortcode |
| CVE-2026-2811 | 5.4 MEDIUM | Ajaxify Comments < 3.2 - Unauthenticated HTTP Header Injection |
| CVE-2026-8151 | 5.4 MEDIUM | Simple Membership MailChimp Integration < 1.9.8 - API Key Update via CSRF |
| CVE-2025-15481 | 5.3 MEDIUM | Notification Bar for WordPress <= 1.1.8 – Unauthenticated Subscriber Data Disclosure |
| CVE-2026-17563 | 5.3 MEDIUM | WP User Frontend < 4.3.11 - Unauthenticated Post Creation via Subscription-Gated Form |
| CVE-2025-8945 | 5.3 MEDIUM | Wp Edit Password Protected < 1.3.5 - Protection Bypass via REST API |
| CVE-2025-15490 | 5.3 MEDIUM | Passster < 4.2.26 - Global Protection Bypass |
| CVE-2026-77793 | 5.3 MEDIUM | RegistrationMagic < 6.0.9.9 - Unauthenticated Payment Bypass via Omitted Price Field |
| CVE-2026-77794 | 5.3 MEDIUM | RegistrationMagic 6.0.0.0 - 6.0.9.8 - Unauthenticated Payment Bypass via Zero Quantity |
| CVE-2025-15489 | 5.3 MEDIUM | Passster < 4.2.24 - Password Protection Bypass |
| CVE-2026-83533 | 5.3 MEDIUM | WP Express Checkout < 2.4.9 - Unauthenticated Payment Bypass via wpec_process_payment |
| CVE-2026-78153 | 5.3 MEDIUM | Restrict User Access 2.6 - 2.8 - Unauthenticated Content Protection Bypass via REST API Ro |
Showing top 20 of 66 CVEs. View all on vendor page → →
No comments yet