Site Reviews WordPress 插件在 8.3.0 版本之前未对请求数据中的反序列化操作进行防护,并通过填充(padding)该站点的 WordPress 非空值密钥(nonce key)来推导用于保护这些数据的密钥。在那些密钥缺失、仍为默认示例值或过短而缺乏保密性的安装环境中,该密钥可被公开计算得出。这使得未认证用户能够在此类环境中注入任意 PHP 对象。由于 Site Reviews 插件 8.3.0 之前的自身代码中不存在从注入对象出发的后续利用链,因此漏洞的影响范围取决于站点上其他代码的具体情
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Site Reviews | 7.2.2 ~ 8.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81431 | Registration Form for WooCommerce 1.1.0 - 1.1.2 - Contributor+ Privilege Escalation via Un | |
| CVE-2026-77770 | miniOrange 2FA (Free & Pro) - Unauthenticated Arbitrary Option Deletion via Out-of-Band Em | |
| CVE-2026-77771 | miniOrange 2FA (Free & Pro) - 2FA Bypass via Session-Scoped OTP Lockout | |
| CVE-2026-78361 | zipMoney(Zip Co) Payments Plugin for WooCommerce < 2.4.0 - Unauthenticated Arbitrary Optio | |
| CVE-2026-19840 | Notiqoo < 1.4.14 - Contributor+ Arbitrary Option Update via Multiple AJAX Actions | |
| CVE-2026-19436 | Ultimate Gift Cards For WooCommerce < 3.2.10 - Unauthenticated Gift Card Value Inflation v | |
| CVE-2026-19439 | Ultimate Gift Cards for WooCommerce 3.0.3 - 3.2.9 - Unauthenticated Gift Card Code and Cus |
No comments yet