The Events Calendar WordPress 插件在 6.17.5.1 版本之前,未对提交至未认证 AJAX 操作的数据进行验证或清理,便在将其合并到渲染上下文之前直接使用,导致未认证的用户能够执行站点上注册的任意短代码。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | The Events Calendar | 6.12.0< 6.17.5.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | The Events Calendar | 6.12.0 ~ 6.17.5.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-19856 | 6.5 MEDIUM | All in One SEO < 5.0.2.1 - Unauthenticated Arbitrary Shortcode Execution via Search Query |
| CVE-2026-92924 | 5.4 MEDIUM | Unlimited Elements For Elementor < 2.0.21 - Subscriber+ Arbitrary Shortcode Execution via |
| CVE-2026-85005 | 5.4 MEDIUM | Popup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invocation via Mis |
| CVE-2026-91020 | 5.3 MEDIUM | WebToffee Gift Cards for WooCommerce < 1.3.1 - Unauthenticated Gift Card Amount Manipulati |
| CVE-2026-90987 | 5.3 MEDIUM | Easy PayPal & Stripe Buy Now Button 1.8 - 2.0.5 - Unauthenticated Payment Amount Manipulat |
| CVE-2026-90952 | 5.3 MEDIUM | WP Edit Password Protected 2.0.0 - 2.0.6 - Unauthenticated Site-Wide Access Mode Bypass vi |
| CVE-2026-13413 | 5.3 MEDIUM | CMP - Coming Soon & Maintenance < 4.1.20 - Unauthenticated Maintenance Mode Bypass via Log |
| CVE-2026-97219 | 4.3 MEDIUM | MStore API 4.21.1 - 4.22.0 - Subscriber+ Payment Bypass via 'status' Parameter |
| CVE-2026-79618 | 4.3 MEDIUM | WP User Frontend < 4.3.12 - Subscriber+ Post Creation via Subscription-Gated Form |
| CVE-2026-1661 | 4.3 MEDIUM | WP Mail Logging < 1.17.0 - Unauthenticated HTML Injection |
| CVE-2026-81740 | Paytm Payment Gateway < 2.8.9 - Unauthenticated Order Status Manipulation via Payment Call | |
| CVE-2026-85004 | Popup Maker WP <= 1.4.5 - Subscriber+ Missing Authorization via sgpm_connect | |
| CVE-2026-91828 | OMGF < 6.3.11 - Unauthenticated DoS via do_optimize | |
| CVE-2026-90988 | Request a Quote <= 2.5.6 - Unauthenticated Quote Request Contact Record Disclosure via emd | |
| CVE-2026-85016 | Unlimited Elements For Elementor < 2.0.21 - Contributor+ Stored XSS via Icon Library Param | |
| CVE-2026-13718 | Tabs Responsive <= 2.5 - Shop Manager+ Stored XSS via WooCommerce Product Tab Content | |
| CVE-2026-91022 | Motors < 1.4.124 - Listing Manager+ Stored XSS via Badge Color | |
| CVE-2026-91023 | Motors – Car Dealership & Classified Listings < 1.4.124 - Subscriber+ Cross-User Post Meta | |
| CVE-2026-94298 | BuildKit < 1.0.29 - Contributor+ Stored SQLi via list_content Parameter | |
| CVE-2026-97318 | Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated Stored Open Redirect via |
Showing top 20 of 22 CVEs. View all on vendor page → →
No comments yet