“To Do List Member”WordPress 插件 1.6 版本及更早版本存在一个安全漏洞:其数据导入功能中缺乏身份验证(authorization)和 CSRF nonce 检查,并且未对导入数据的来源位置进行验证。这可能导致未经身份验证的用户在网站上创建任意已发布的文章和分类项(taxonomy terms)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | To Do List Member | 1.4 ~ 1.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85113 | 6.5 MEDIUM | GiveWP < 4.16.9 - Unauthenticated Arbitrary Shortcode Execution via Donor Name |
| CVE-2026-92400 | 5.3 MEDIUM | Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via San |
| CVE-2026-85010 | 5.3 MEDIUM | RestroPress < 3.4.6 - Unauthenticated Price Manipulation via Cart Add-ons |
| CVE-2026-82187 | WooCommerce Online Product Designer 1.7.0 - < 2.15.0 - Unauthenticated Arbitrary File Uplo |
No comments yet