在 BackWPup WordPress 插件版本 5.7.7 之前,该插件未验证对其由 cron 触发的备份执行处理程序的请求是否确实源自 WordPress 的内部计划事件分发机制,这使得未经身份验证的攻击者能够强制立即运行任何现有的备份作业,而与该作业配置的触发类型或计划无关。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93509 | 6.5 MEDIUM | Wallet System for WooCommerce 2.0.0 - 2.7.10 - Subscriber+ Wallet Balance Manipulation via |
| CVE-2026-103517 | 5.3 MEDIUM | Airwallex Online Payments Gateway < 1.36.0 - Unauthenticated Payment Bypass via Forged Web |
| CVE-2026-104671 | 5.3 MEDIUM | TutorStarter < 4.0.4 - Unauthenticated User Registration Bypass via AJAX |
| CVE-2026-105190 | 5.3 MEDIUM | Easy Digital Downloads < 3.7.1 - Unauthenticated Account Creation with Registration Disabl |
| CVE-2026-103309 | GPTranslate < 2.34.14 - Unauthenticated Stored XSS via REST API Translation Storage | |
| CVE-2026-103646 | Ultimate Multisite < 2.17.0 - Unauthenticated Authentication Bypass via 'email_address' Pa | |
| CVE-2026-104646 | Image Photo Gallery Final Tiles Grid < 3.6.14 - Contributor+ Stored XSS via Gallery Shortc | |
| CVE-2026-104645 | Image Photo Gallery Final Tiles Grid < 3.6.14 - Contributor+ Arbitrary Gallery Cloning, Im | |
| CVE-2026-103692 | Frontend Dashboard 3.0.0 - 3.0.4 - Unauthenticated Privilege Escalation via Arbitrary Func | |
| CVE-2026-105195 | Booking Calendar 10.15 - 11.8.2 - Editor+ Arbitrary Option Disclosure | |
| CVE-2026-105197 | LatePoint < 5.6.5 - Agent+ Arbitrary Order, Customer and Transaction Deletion via IDOR | |
| CVE-2026-105198 | LatePoint < 5.7.3 - Unauthenticated Customer PII Disclosure via IDOR | |
| CVE-2026-105194 | Easy Digital Downloads < 3.7.1 - Subscriber+ Sensitive Information Disclosure via User Dow | |
| CVE-2026-105196 | LatePoint < 5.6.9 - Agent+ Cross-Agent Data Disclosure and Modification via Abilities API | |
| CVE-2026-105193 | Booking Calendar < 11.8 - Unauthenticated Booking Information Disclosure and Modification | |
| CVE-2026-86826 | BackWPup < 5.7.7 - Unauthenticated Sensitive Data Disclosure via Restore Working Directory | |
| CVE-2026-86828 | BackWPup < 5.7.7 - Admin+ Path Traversal to RCE via Restore PclZip Fallback | |
| CVE-2026-105260 | Database Addon For WPForms < 1.1.1 - Arbitrary Form Entry Deletion via CSRF | |
| CVE-2026-94246 | Wallet System for WooCommerce 2.0.0 - 2.7.10 - Subscriber+ Forged Wallet Withdrawal Reques | |
| CVE-2026-94244 | Wallet System for WooCommerce < 2.8.0 - Subscriber+ Store-Wide Wallet Transaction Disclosu |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet