在 2.15.0 版本之前的 Web to Print Online Designer WordPress 插件未对上传文件的类型或扩展名进行验证,并且会将保护这些上传文件的令牌提供给任何索取的访客,使得未认证的攻击者能够上传任意文件(包括 PHP 文件),从而在服务器上执行代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Web to Print Online Designer | 1.7.0 ~ 2.15.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85113 | 6.5 MEDIUM | GiveWP < 4.16.9 - Unauthenticated Arbitrary Shortcode Execution via Donor Name |
| CVE-2026-92400 | 5.3 MEDIUM | Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via San |
| CVE-2026-85010 | 5.3 MEDIUM | RestroPress < 3.4.6 - Unauthenticated Price Manipulation via Cart Add-ons |
| CVE-2026-86802 | 3.7 LOW | To Do List Member 1.4 - 1.6 - Unauthenticated Content Injection via Import |
No comments yet