Eventin WordPress 插件在 4.1.22 版本之前,未对其事件管理相关的多个 REST API 路由进行适当的权限校验。这使得拥有“贡献者”(Contributor)及以上权限的用户能够: 1. 将网站的前端主页设置修改为一个他们并不拥有的事件; 2. 创建、编辑和删除全局的事件(event)和演讲者(speaker)分类法术语(taxonomy terms),而按照权限设计,这些用户本不应有权管理这些内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77826 | RegistrationMagic 5.0.1.8 - 6.0.9.8 - Unauthenticated Authentication Bypass via Missing Fa | |
| CVE-2026-82304 | Music Store – WordPress eCommerce < 1.4.5 - Unauthenticated SQLi via paypal-data Handler | |
| CVE-2026-81424 | Accept Stripe Payments < 2.1.4 - Unauthenticated Product Substitution via IDOR | |
| CVE-2026-83543 | Greenshift < 13.2.0 - Contributor+ SSRF via get-csv-to-json REST Endpoint | |
| CVE-2026-83544 | Greenshift < 13.2.0 - Contributor+ Stored XSS via Block Animation customProps Attribute | |
| CVE-2026-81423 | Accept Stripe Payments < 2.1.4 - Open Redirect via IPN Handler | |
| CVE-2026-81348 | My Private Site < 4.2.3 - Unauthenticated Sensitive Information Exposure via RSS Feeds and | |
| CVE-2026-81404 | IPGP Visitors Origin < 1.6 - Reflected XSS | |
| CVE-2026-78362 | SEO Flow by LupsOnline 3.0.0 - 3.0.2 - Unauthenticated Privilege Escalation via API Key Au | |
| CVE-2026-82846 | Masteriyo LMS 1.18.0 - 2.3.3 - Instructor+ Stored XSS via Course Custom Fields | |
| CVE-2026-78149 | Post Carousel 4.0.0 - 4.0.7 - Unauthenticated Password-Protected Post Content and post_pas | |
| CVE-2026-78150 | Post Carousel 4.0.0 - 4.0.7 - Contributor+ Private and Protected Post Content Disclosure v | |
| CVE-2026-19861 | JetFormBuilder < 3.6.5.2 - Unauthenticated Stored XSS via WYSIWYG Field in Notification Em | |
| CVE-2026-15247 | Search Atlas SEO < 2.6.24 - Subscriber+ Google Service Account Credential Overwrite/Deleti | |
| CVE-2026-19858 | JetFormBuilder < 3.6.5.2 - Unauthenticated Password Hash and Arbitrary Metadata Disclosure | |
| CVE-2025-15694 | Joli Table Of Contents 2.0.0 - 2.8.0 - Admin+ Stored XSS | |
| CVE-2025-15693 | JCH Optimize 4.2.1 - 5.0.0 - Admin+ Path Traversal | |
| CVE-2026-84937 | YT Player < 2.1.0 - Contributor+ SQLi via ytp_ajax | |
| CVE-2026-84021 | Bold Page Builder < 5.9.8 - Contributor+ Stored XSS via bt_bb_button/bt_bb_headline/bt_bb_ | |
| CVE-2026-84022 | Bold Page Builder < 5.9.8 - Contributor+ Stored XSS via Multiple Shortcode Element Attribu |
Showing top 20 of 34 CVEs. View all on vendor page → →
No comments yet