Restaurant Menu and Food Ordering 插件(WordPress 插件)在 2.4.12 之前的版本未验证 PayPal 支付通知是否确实来自 PayPal,这使得未认证的恶意用户可以伪造支付通知,从而在未完成实际付款的情况下,将自己的订单标记为“已付款”且状态为“已完成”。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Restaurant Menu and Food Ordering | < 2.4.12 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Restaurant Menu and Food Ordering | 0 ~ 2.4.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82923 | 9.8 CRITICAL | AI Website Builder (GitHub build) 1.0.0 - Unauthenticated RCE via Unprotected REST Routes |
| CVE-2026-84045 | 5.3 MEDIUM | E-cab Taxi Booking Manager for Woocommerce < 2.0.5 - Unauthenticated Price Manipulation vi |
| CVE-2026-84043 | 5.3 MEDIUM | ePayco Payment Gateway for WooCommerce < 8.4.7 - Unauthenticated Payment Confirmation Bypa |
| CVE-2026-79632 | WPFunnels < 3.13.0 - Unauthenticated Arbitrary Recipient Email Sending via wpfnl_shortcode | |
| CVE-2026-84066 | Directorist < 8.9 - Subscriber+ Arbitrary Post Meta Write via atbdp_post_attachment_upload | |
| CVE-2026-84146 | Xpro Elementor Addons < 1.7.8 - Unauthenticated Draft/Private Product Disclosure via Quick | |
| CVE-2026-82186 | WPLP Cookie Consent < 4.4.2 - Admin+ SQLi via 'offset' Parameter | |
| CVE-2026-82194 | WPvivid Backup & Migration < 0.9.134 - Admin+ Arbitrary File Deletion via Path Traversal | |
| CVE-2026-82193 | WPvivid Backup & Migration < 0.9.134 - Admin+ File Write Outside the Backup Directory via | |
| CVE-2026-74853 | Pods < 3.3.9.2 - Author+ Arbitrary File Read via Shortcode Display Callback | |
| CVE-2026-79631 | WPFunnels < 3.13.0 - Unauthenticated Order and Opt-In PII Disclosure via Web-Accessible Lo | |
| CVE-2026-80438 | Ninja Forms 3.14.0 - 3.15.1 - Authenticated Arbitrary Post Modification and Sensitive Info | |
| CVE-2026-81347 | Frontend Admin by DynamiApps < 3.29.13 - Unauthenticated .htaccess and index.php Deletion | |
| CVE-2025-15691 | WPFunnels < 3.13.0 - Unauthenticated User Registration via Opt-in Forms | |
| CVE-2026-79630 | WPFunnels < 3.13.0 - Unauthenticated Price Manipulation via Order Bump Product ID Substitu | |
| CVE-2026-17517 | Content Views < 4.5.1.2 - Unauthenticated Non-Public Post Content Disclosure via Views Sta | |
| CVE-2026-19224 | Hummingbird < 3.21.2 - Admin+ Network-Wide RCE via Hub Connector on Multisite | |
| CVE-2026-16281 | Classified Listing < 6.1.1 - Subscriber+ Arbitrary Attachment Deletion and Listing Image T |
No comments yet