在 4.16.9 之前,GiveWP WordPress 插件在未对捐赠者提交的值进行渲染以显示在公共页面前,未移除其中的短代码分隔符(shortcode delimiters)。此外,该插件用于剥离短代码的机制可通过嵌套方式被绕过,从而使未经认证的用户能够执行网站上注册的任何短代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92400 | 5.3 MEDIUM | Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via San |
| CVE-2026-85010 | 5.3 MEDIUM | RestroPress < 3.4.6 - Unauthenticated Price Manipulation via Cart Add-ons |
| CVE-2026-86802 | 3.7 LOW | To Do List Member 1.4 - 1.6 - Unauthenticated Content Injection via Import |
| CVE-2026-82187 | WooCommerce Online Product Designer 1.7.0 - < 2.15.0 - Unauthenticated Arbitrary File Uplo |
No comments yet