Hoo Companion WordPress 插件 1.0.2 版本的其中一个导入功能缺乏任何授权或验证机制,且在将提交的数据存储为当前激活主题的设置之前未对其进行净化处理。这使得未认证的 attackers(攻击者)能够注入任意 Web 脚本,这些脚本会在任何人(包括管理员)浏览该网站时执行。此外,同一请求会覆盖并破坏网站现有的主题设置。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Hoo Companion | 1.0.2 ~ 1.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81648 | 10.0 CRITICAL | CryptoPayment Gateway 1.2.1 - 1.2.2 - Unauthenticated Arbitrary File Deletion and Settings |
| CVE-2026-74933 | 8.8 HIGH | GenieWords 1.5.27 - 1.5.34 - Unauthenticated Stored XSS and Configuration Overwrite |
| CVE-2026-88793 | 8.8 HIGH | YouTube Embed 10.0 - 10.3 - Unauthenticated Stored XSS via youram_server |
| CVE-2026-88802 | 7.5 HIGH | MDJM Event Management and Mobile Events Manager - Unauthenticated Arbitrary Post Deletion |
| CVE-2026-89050 | 4.3 MEDIUM | Quads Ads Manager for Google AdSense < 3.0.5 - Subscriber+ Ad-Selling Payment Bypass via U |
| CVE-2026-77773 | Social Contact Form (FormyChat) < 2.15.8 - Unauthenticated Gravity Forms Entry Disclosure | |
| CVE-2026-86406 | User Registration & Membership < 5.2.8 - Subscriber+ Privilege Escalation via Membership P | |
| CVE-2026-80071 | User Registration & Membership < 5.2.8 - Author+ Privilege Escalation to Administrator | |
| CVE-2026-80072 | User Registration & Membership < 5.2.8 - Unauthenticated Open Redirect via Login Redirect | |
| CVE-2026-86407 | User Registration & Membership < 5.2.8 - Unauthenticated User Data Disclosure via Membersh | |
| CVE-2026-88764 | Simple Membership < 4.7.8 - Subscriber+ Membership Level Escalation via PayPal Standard su | |
| CVE-2026-88912 | rtMedia for WordPress, BuddyPress and bbPress < 4.7.12 - Subscriber+ Arbitrary Activity Pr | |
| CVE-2026-88995 | Bookit < 2.6.0.1 - Unauthenticated Appointment PII Disclosure via Availability Check | |
| CVE-2026-89080 | Really Simple Security < 9.8.1 - Unauthenticated 2FA Bypass via Email Provider State Demot |
No comments yet