WPCafe WordPress 插件在 3.0.21 版本之前未对其部分 REST API 端点实施访问限制,导致未认证的攻击者能够读取 WooCommerce 的产品数据,包括每个产品的销售数量、精确库存水平以及私有产品元数据。这些数据在 WooCommerce 中本身是受身份验证保护的。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82211 | 8.2 HIGH | Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Completion and Order Key Disclosure |
| CVE-2026-82212 | 7.5 HIGH | Nexi XPay Build <= 7.6.2 - Unauthenticated Payment Bypass via NPG Notification Handler |
| CVE-2026-86833 | 5.4 MEDIUM | MetForm < 4.3.1 - Unauthenticated HTML Injection in Notification Emails via Field Shortcod |
| CVE-2026-105322 | 5.3 MEDIUM | Magee Shortcodes <= 2.1.1 - Unauthenticated Mail Relay via Contact Form |
| CVE-2026-103323 | Integration for Epos Now and WooCommerce 4.6.0 - 4.11.1 - Unauthenticated Action Scheduler | |
| CVE-2026-104049 | Academy LMS < 4.0.0 - Subscriber+ Arbitrary Lesson Content Disclosure via Topic REST Endpo | |
| CVE-2026-104651 | Yaad Sarig Payment Gateway For WC < 2.2.13 - Subscriber+ Arbitrary Order Payment Manipulat | |
| CVE-2026-104652 | Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Image ID | |
| CVE-2026-104050 | Academy LMS < 4.0.0 - Subscriber+ Cross-Course Quiz Answer Disclosure via render_quiz_answ | |
| CVE-2026-103681 | Frontend Dashboard < 3.0.0 - Subscriber+ Profile and Post Field Deletion via fed_user_prof | |
| CVE-2026-103378 | Geliver Akıllı Kargo Pazaryeri 3.0.0 - 3.1.0 - Unauthenticated API Key Disclosure via Publ | |
| CVE-2026-104653 | Envira Gallery < 1.16.1 - Author+ Stored XSS via Gallery Crop Dimensions | |
| CVE-2026-104953 | MPG < 4.2.3 - Editor+ SQLi via Project Import | |
| CVE-2026-104677 | WP Coder 4.0 - 4.5.1 - Editor+ RCE via Global PHP | |
| CVE-2026-104667 | Animated Number Counters < 3.1 - Editor+ Second-Order SQLi via Counter Order | |
| CVE-2026-104678 | CP Media Player < 1.3.4 - Contributor+ Media Player Settings Update | |
| CVE-2026-105316 | Magee Shortcodes <= 2.1.1 - Reflected XSS via live_preview and magee_create_shortcode Acti | |
| CVE-2026-87971 | If-So Dynamic Content 1.4.4 - 1.10.1 - Reflected XSS via 'message' Parameter | |
| CVE-2026-87782 | Koinonia Link 1.1.2 - 1.1.4 - Subscriber+ Privilege Escalation to Administrator | |
| CVE-2026-97188 | String Locator < 2.6.8 - Unauthenticated PHP Object Injection via Database Editor |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet