RestroPress WordPress 插件在 3.4.6 版本之前,当商品被添加到购物车或更新时,未在服务器端对客户端提供的附加组件价格进行验证,这允许未经身份验证的用户设置任意价格,并以攻击者指定的总金额(包括零)下单。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | RestroPress | 0 ~ 3.4.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85113 | 6.5 MEDIUM | GiveWP < 4.16.9 - Unauthenticated Arbitrary Shortcode Execution via Donor Name |
| CVE-2026-92400 | 5.3 MEDIUM | Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via San |
| CVE-2026-86802 | 3.7 LOW | To Do List Member 1.4 - 1.6 - Unauthenticated Content Injection via Import |
| CVE-2026-82187 | WooCommerce Online Product Designer 1.7.0 - < 2.15.0 - Unauthenticated Arbitrary File Uplo |
No comments yet