WordPress 插件 Tutor LMS 在 4.1.1 版本之前存在一个漏洞,该漏洞未验证课程内容排序请求中所提到的文章是否属于请求者管理的课程。这使得拥有“讲师”级别权限的用户可以重新分配网站上任意文章的父级文章,从而将其他讲师的课程内容转移至自己的课程中,并导致任意已发布的文章变得无法访问。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94256 | SMS Alert 4.0.0 - Unauthenticated Authentication Bypass via Login with OTP | |
| CVE-2026-94257 | SMS Alert 3.9.6 - 4.0.0 - Unauthenticated Privilege Escalation via Arbitrary Password Rese | |
| CVE-2026-87780 | LTL Freight Quotes – Old Dominion Edition < 4.2.19 - Unauthenticated Stored XSS via Shippi | |
| CVE-2026-87781 | LTL Freight Quotes – Old Dominion Edition 4.2.11 - 4.2.18 - Unauthenticated SQLi via Shipp | |
| CVE-2026-105995 | Booking Package < 1.7.30 - Unauthenticated Booking Customer PII Disclosure | |
| CVE-2026-105990 | Accept PayPal Payments Using Contact Form 7 < 4.0.7 - Unauthenticated PII Disclosure via C | |
| CVE-2026-107321 | W3 Total Cache < 2.10.6 - Author+ Path Traversal via CDN Media Library Import | |
| CVE-2026-107120 | Contest Gallery < 33.0.1 - Unauthenticated Email Verification Bypass via Brute-Forceable R | |
| CVE-2026-107323 | Gallery PhotoBlocks 1.3.5 - Contributor+ Stored XSS | |
| CVE-2026-105976 | Portfolio Filter Gallery < 2.2.1 - Contributor+ Missing Authorization via Multiple AJAX Ac | |
| CVE-2026-105989 | Accept PayPal Payments using Contact Form 7 < 4.0.7 - Unauthenticated Transaction Status F | |
| CVE-2026-105977 | Portfolio Filter Gallery 2.0.2 - 2.2.0 - Contributor+ Cross-User Video Thumbnail Deletion | |
| CVE-2026-104754 | Rank Math SEO < 1.0.280 - Admin+ Stored XSS via Redirection Source URL | |
| CVE-2026-104752 | Rank Math SEO < 1.0.280 - Admin+ Arbitrary File Upload to RCE via Settings Import | |
| CVE-2026-104753 | Rank Math SEO < 1.0.280 - Admin+ SQLi via 'per_page' Parameter |
No comments yet