在2.4.0版本之前的Five Star Business Profile and Schema WordPress插件中,用于解析模式字段默认值的回调函数未得到适当限制,导致具备作者级及以上权限的已认证用户能够存储会泄露敏感数据的输入,包括其他用户的密码哈希值和任意网站选项值,这些信息会被存储在公开输出中,可供未认证的访客读取。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Five Star Business Profile and Schema | 2.3.20 ~ 2.4.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93549 | CoCart 4.9.0 - 4.9.6 - Administrator Account Creation via REST API Authentication Bypass | |
| CVE-2026-97332 | User Private Files < 2.2.0 - Unauthenticated Private File Disclosure via .htaccess Rewrite | |
| CVE-2026-17005 | Horizontal Scrolling Announcements <= 2.6 - Contributor+ Stored XSS via Style Field | |
| CVE-2026-104118 | Razorpay for WooCommerce < 4.8.8 - Unauthenticated Order Shipping Modification via IDOR | |
| CVE-2026-104119 | Simple Shopping Cart < 5.2.6 - Admin+ Stored XSS via PayPal API Credentials |
No comments yet