LearnPress WordPress 插件在 4.4.7 版本之前,存在一个漏洞:该插件在公共页面上使用用户提供的值作为 HTML 属性时,未对其进行适当的转义处理。这使得未认证的恶意攻击者能够构造特制的链接,当任何用户(包括已登录的管理员)在浏览器中打开该链接时,即可在其浏览器中执行任意 JavaScript 代码。需要注意的是,该漏洞仅影响使用经典编辑器(非块编辑器)的网站。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | LearnPress | 4.2.6.4< 4.4.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | LearnPress | 4.2.6.4 ~ 4.4.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-13407 | 6.1 MEDIUM | Royal Elementor Addons < 1.7.1067 - Unauthenticated Stored HTML Injection in Form Notifica |
| CVE-2026-84906 | 5.3 MEDIUM | Eventin < 4.1.24 - Unauthenticated Payment Bypass via Stripe and PayPal Cross-Order Transa |
| CVE-2026-86475 | 5.3 MEDIUM | Appointment Hour Booking < 1.5.95 - Unauthenticated Booking Capacity Bypass via Multi-Appo |
| CVE-2026-19857 | 4.8 MEDIUM | Formidable Forms < 6.35 - Unauthenticated Arbitrary Shortcode Execution via [entry_key] Cu |
| CVE-2026-76552 | WP Import Export Lite < 3.9.33 - Authenticated Arbitrary File Upload via Remote Image Impo | |
| CVE-2026-84907 | Eventin < 4.1.24 - Unauthenticated Order and Attendee Status Reset via Payment REST Endpoi | |
| CVE-2026-76555 | WP Import Export Lite < 3.9.33 - Authenticated Sensitive File Disclosure via Existing File | |
| CVE-2026-76557 | WP Import Export Lite < 3.9.33 - Authenticated SQLi via Import Options | |
| CVE-2026-76551 | WP Import Export Lite < 3.9.33 - Authenticated RCE via Export Field PHP Function | |
| CVE-2026-74926 | MultiVendorX 5.0.0 - 5.0.15 - Subscriber+ Arbitrary Store Data and Ownership Overwrite via | |
| CVE-2026-76553 | WP Import Export Lite < 3.9.33 - Authenticated Arbitrary Directory Deletion via Template P | |
| CVE-2026-78472 | Ni WooCommerce Sales Report < 4.2.0 - Unauthenticated SQLi via 'sort' Parameter | |
| CVE-2026-82124 | Schema & Structured Data for WP & AMP < 1.66 - Unauthenticated Password-Protected Post Con | |
| CVE-2026-77702 | Eventin < 4.1.24 - Unauthenticated Ticket Price Rewrite via order_token | |
| CVE-2026-84829 | Optimole < 4.2.12 - Unauthenticated Stored XSS via Srcset Descriptor Parameter | |
| CVE-2026-84905 | Eventin < 4.1.24 - Contributor+ User Creation via Speaker Creation | |
| CVE-2026-84088 | Xpro Elementor Addons < 1.7.9 - Contributor+ Stored XSS via Interactive Circle Widget | |
| CVE-2026-82126 | Schema & Structured Data for WP & AMP 1.63 - 1.65 - Contributor+ Non-Public Post Content D | |
| CVE-2026-82125 | Schema & Structured Data for WP & AMP 1.46 - 1.65 - Unauthenticated Non-Public Comment Con | |
| CVE-2026-76550 | WP Import Export Lite < 3.9.34 - Authenticated RCE via Export Template Path Traversal |
Showing top 20 of 46 CVEs. View all on vendor page → →
No comments yet