WooCommerce 注册表单(Registration Form)插件在 1.1.3 版本之前未验证注册过程中引用的表单是否为合法的注册表单,而是从攻击者可控的任意文章(post)中读取允许的角色白名单。因此,能够创建文章的用户(Contributor 及以上权限)可以注册新账户并指定任意角色(包括管理员),从而导致站点被完全接管。此漏洞是 CVE-2026-54807 的不完全修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Registration Form for WooCommerce | 1.1.0 ~ 1.1.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82925 | Site Reviews 7.2.2 - 8.2.2 - Unauthenticated PHP Object Injection via Form Signature | |
| CVE-2026-77770 | miniOrange 2FA (Free & Pro) - Unauthenticated Arbitrary Option Deletion via Out-of-Band Em | |
| CVE-2026-77771 | miniOrange 2FA (Free & Pro) - 2FA Bypass via Session-Scoped OTP Lockout | |
| CVE-2026-78361 | zipMoney(Zip Co) Payments Plugin for WooCommerce < 2.4.0 - Unauthenticated Arbitrary Optio | |
| CVE-2026-19840 | Notiqoo < 1.4.14 - Contributor+ Arbitrary Option Update via Multiple AJAX Actions | |
| CVE-2026-19436 | Ultimate Gift Cards For WooCommerce < 3.2.10 - Unauthenticated Gift Card Value Inflation v | |
| CVE-2026-19439 | Ultimate Gift Cards for WooCommerce 3.0.3 - 3.2.9 - Unauthenticated Gift Card Code and Cus |
No comments yet