Bookly WordPress 插件在 28.3 版本之前未能在更新客户存储的信息之前正确验证客户身份,使得知道客户主标识符的未认证攻击者能够覆盖该客户的个人存储信息,如姓名、电子邮件和地址。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-80514 | 5.3 MEDIUM | wpForo Forum 3.0.0 - 3.1.5 - Unauthenticated AI Credit Exhaustion via IP Rate Limit Bypass |
| CVE-2026-88848 | 4.2 MEDIUM | MasterStudy LMS 1.9 - < 3.7.50 - Subscriber+ Membership Plan Quota and Category Restrictio |
| CVE-2026-78394 | Link Library < 7.9.6 - Contributor+ Path Traversal via 'filepath' Parameter | |
| CVE-2026-78397 | Link Library < 7.9.6 - Unauthenticated SSRF via Reciprocal Link Validation | |
| CVE-2026-78393 | Link Library < 7.9.6 - Reflected XSS via 'link_tags' and 'link_price' Sort and Breadcrumb |
No comments yet