Kirki WordPress 插件在 6.3.0 版本之前,在渲染并返回页面内容时,未检查请求者是否有权读取该文章,这使得未认证用户可以获取非公开可用页面的内容,例如私有文章、草稿、待审文章和已放入回收站的文章。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-19855 | 6.5 MEDIUM | Spam protection, Honeypot, Anti-Spam by CleanTalk < 6.87 - Unauthenticated Arbitrary Short |
| CVE-2026-85117 | 6.5 MEDIUM | Contact Form 7 Captcha 0.1.7 - 0.1.8 - Unauthenticated Arbitrary Shortcode Execution via F |
| CVE-2026-83537 | 5.3 MEDIUM | WP Express Checkout < 2.5.0 - Unauthenticated Payment Bypass via wpec_process_empty_paymen |
| CVE-2026-80440 | 4.8 MEDIUM | Hustle < 7.8.14.2 - Unauthenticated Arbitrary Shortcode Execution via Success Message Plac |
| CVE-2025-15690 | Content Mask 1.7.1 - 1.8.5.5 - Contributor+ Stored XSS via Post Scripts and Styles | |
| CVE-2026-13144 | WP Travel < 12.0.2 - Unauthenticated Arbitrary Booking Payment Reset | |
| CVE-2026-13146 | WP Travel < 12.0.2 - Unauthenticated Booking Payment State Tampering via IDOR | |
| CVE-2026-14962 | ELEX WooCommerce Request a Quote < 2.4.1 - Unauthenticated SQLi via variation_id | |
| CVE-2026-18042 | WP Travel < 12.0.2 - Unauthenticated Arbitrary Booking Cancellation | |
| CVE-2026-16960 | Loops & Logic < 4.3.0 - Unauthenticated User Data and Site Option Disclosure | |
| CVE-2026-75861 | Ultimate Gift Cards for WooCommerce < 3.2.10 - Subscriber+ Gift Card Theft and Destruction | |
| CVE-2026-80339 | Payment Plugins for Stripe WooCommerce < 4.0.12 - Unauthenticated Customer PII Disclosure | |
| CVE-2026-80340 | Payment Plugins for PayPal WooCommerce < 2.0.26 - Unauthenticated Customer PII Disclosure | |
| CVE-2026-80341 | Payment Plugins for PayPal WooCommerce < 2.0.26 - Subscriber+ Stored Payment Method Assign | |
| CVE-2026-81021 | SupportCandy 3.2.9 - 3.5.2 - Unauthenticated Ticket Attachment Disclosure | |
| CVE-2026-81741 | Groundhogg < 4.7.2 - Open Redirect via 'redirect_to' Parameter | |
| CVE-2026-81022 | SupportCandy 3.3.6 - 3.5.2 - Unauthenticated Ticket Content Disclosure via Auth Code Leak | |
| CVE-2026-82185 | WPLP Cookie Consent < 4.4.2 - Subscriber+ Banner Settings Overwrite and A/B Test Data Rese | |
| CVE-2026-82848 | Masteriyo LMS 1.3.1 - 2.3.3 - Unauthenticated Course Enrollment Disclosure | |
| CVE-2026-82184 | WPLP Cookie Consent < 4.4.2 - Unauthenticated IAB TCF Consent Option Update |
Showing top 20 of 28 CVEs. View all on vendor page → →
No comments yet