WPForms Lite WordPress 插件(版本范围 1.5.0.1 至 2.0.2)在处理用户提交的表单字段值时,未移除其中的 shortcode 分隔符,便直接将其写回渲染后的表单中。该漏洞允许未认证的远程攻击者在网站上执行任意已注册的 shortcode,并可读取非公开文章所属附件的详细信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88828 | 5.4 MEDIUM | Blacklist Manager for WooCommerce 1.3.0 - 2.3.1 - Blocked User Restriction Bypass via XML- |
| CVE-2026-92996 | 5.3 MEDIUM | Verge3D 4.1.0 - 4.13.0 - Unauthenticated Payment Bypass via v3d_payment_done |
| CVE-2026-89411 | 5.3 MEDIUM | Paymattic < 4.6.26 - Unauthenticated Payment Bypass via Unbound Stripe PaymentIntent |
| CVE-2026-86838 | 5.3 MEDIUM | Bookly < 28.3 - Unauthenticated Payment Bypass via Booking Price Manipulation |
| CVE-2026-93000 | SPS-Suite <= 1.4.0 - Unauthenticated Time-Based SQLi via Search | |
| CVE-2026-89300 | WP Verify API <= 1.0.0 - Unauthenticated Verification Code Email Sending to Arbitrary Reci | |
| CVE-2026-89303 | Post Voting System <= 1.0 - Subscriber+ SQLi via 'row' Parameter |
No comments yet