Slider Pro WordPress 插件(版本 1.0.0 及之前)在其某个 AJAX 操作中未执行任何权限或授权检查,导致未认证用户可以获取非公开文章的标题、摘要和固定链接,包括草稿、待审核、已计划、私有和已删除的文章,以及文章修订版本和媒体元数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Slider Pro | 0 ~ 1.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94299 | elegro Crypto Payment <= 1.0.1 - Unauthenticated Arbitrary Order Status Change via IPN Cal | |
| CVE-2026-94270 | Deema Payment Gateway <= 1.1.2 - Unauthenticated Payment Bypass and Order Manipulation via | |
| CVE-2026-94278 | File Media Renamer <= 1.3 - Author+ Arbitrary File Rename via save-attachment-compat | |
| CVE-2026-94271 | Deema Payment Gateway <= 1.1.2 - Unauthenticated Payment Confirmation Forgery via Unverifi | |
| CVE-2026-89289 | Fast Courier <= 5.2.3 - Unauthenticated Order Fulfillment Update via order-status-update R |
No comments yet