Bookly WordPress 插件在 28.3 版本之前,在计算预约总价时未对客户端提交的预订数量值进行服务端验证,这允许未经身份验证的用户将总价降至零,从而绕过支付步骤并免费预订付费服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84744 | 6.5 MEDIUM | WPForms Lite 1.5.0.1 - 2.0.2 - Unauthenticated Arbitrary Shortcode Execution via Form Fiel |
| CVE-2026-88828 | 5.4 MEDIUM | Blacklist Manager for WooCommerce 1.3.0 - 2.3.1 - Blocked User Restriction Bypass via XML- |
| CVE-2026-92996 | 5.3 MEDIUM | Verge3D 4.1.0 - 4.13.0 - Unauthenticated Payment Bypass via v3d_payment_done |
| CVE-2026-89411 | 5.3 MEDIUM | Paymattic < 4.6.26 - Unauthenticated Payment Bypass via Unbound Stripe PaymentIntent |
| CVE-2026-93000 | SPS-Suite <= 1.4.0 - Unauthenticated Time-Based SQLi via Search | |
| CVE-2026-89300 | WP Verify API <= 1.0.0 - Unauthenticated Verification Code Email Sending to Arbitrary Reci | |
| CVE-2026-89303 | Post Voting System <= 1.0 - Subscriber+ SQLi via 'row' Parameter |
No comments yet