在 Eventin WordPress 插件 4.1.24 版本之前,当添加演讲者时,插件未验证用户是否具备创建账户的权限。这使得拥有“贡献者”(Contributor)及以上权限的用户能够创建新的 WordPress 用户账户,而这些新账户所拥有的权限超过了创建者自身的权限范围,包括发布内容和上传文件的权限。此外,攻击者可以通过提供一个自己控制的电子邮箱地址,获取该新建账户的有效登录凭证。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-13407 | 6.1 MEDIUM | Royal Elementor Addons < 1.7.1067 - Unauthenticated Stored HTML Injection in Form Notifica |
| CVE-2026-84906 | 5.3 MEDIUM | Eventin < 4.1.24 - Unauthenticated Payment Bypass via Stripe and PayPal Cross-Order Transa |
| CVE-2026-86475 | 5.3 MEDIUM | Appointment Hour Booking < 1.5.95 - Unauthenticated Booking Capacity Bypass via Multi-Appo |
| CVE-2026-19857 | 4.8 MEDIUM | Formidable Forms < 6.35 - Unauthenticated Arbitrary Shortcode Execution via [entry_key] Cu |
| CVE-2026-76552 | WP Import Export Lite < 3.9.33 - Authenticated Arbitrary File Upload via Remote Image Impo | |
| CVE-2026-85349 | FluentBoards < 2.0.15 - Subscriber+ Private Board Membership Disclosure via IDOR | |
| CVE-2026-76555 | WP Import Export Lite < 3.9.33 - Authenticated Sensitive File Disclosure via Existing File | |
| CVE-2026-76557 | WP Import Export Lite < 3.9.33 - Authenticated SQLi via Import Options | |
| CVE-2026-76551 | WP Import Export Lite < 3.9.33 - Authenticated RCE via Export Field PHP Function | |
| CVE-2026-74926 | MultiVendorX 5.0.0 - 5.0.15 - Subscriber+ Arbitrary Store Data and Ownership Overwrite via | |
| CVE-2026-76553 | WP Import Export Lite < 3.9.33 - Authenticated Arbitrary Directory Deletion via Template P | |
| CVE-2026-78472 | Ni WooCommerce Sales Report < 4.2.0 - Unauthenticated SQLi via 'sort' Parameter | |
| CVE-2026-82124 | Schema & Structured Data for WP & AMP < 1.66 - Unauthenticated Password-Protected Post Con | |
| CVE-2026-77702 | Eventin < 4.1.24 - Unauthenticated Ticket Price Rewrite via order_token | |
| CVE-2026-84829 | Optimole < 4.2.12 - Unauthenticated Stored XSS via Srcset Descriptor Parameter | |
| CVE-2026-84088 | Xpro Elementor Addons < 1.7.9 - Contributor+ Stored XSS via Interactive Circle Widget | |
| CVE-2026-82126 | Schema & Structured Data for WP & AMP 1.63 - 1.65 - Contributor+ Non-Public Post Content D | |
| CVE-2026-82125 | Schema & Structured Data for WP & AMP 1.46 - 1.65 - Unauthenticated Non-Public Comment Con | |
| CVE-2026-84907 | Eventin < 4.1.24 - Unauthenticated Order and Attendee Status Reset via Payment REST Endpoi | |
| CVE-2026-76550 | WP Import Export Lite < 3.9.34 - Authenticated RCE via Export Template Path Traversal |
Showing top 20 of 46 CVEs. View all on vendor page → →
No comments yet