Livees Checkout WordPress 插件(版本 7.0.2 及更早版本)在订单确认页面对请求参数进行处理前,未进行任何权限检查、nonce 验证或订单密钥校验,导致未认证用户可以更改任意订单的状态、向订单中存储任意数据和备注,并恢复其订单密钥。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Livees Checkout | 6.8 ~ 7.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89235 | 6.8 MEDIUM | Testimonials by BestWebSoft 1.0.5 - 1.0.8 - Unauthenticated SQLi via 'offset' Parameter |
| CVE-2026-103329 | 5.3 MEDIUM | Super Payments < 1.43.1 - Unauthenticated Payment Confirmation Forgery via Webhook Signatu |
| CVE-2026-87846 | 5.3 MEDIUM | Shipping for Nova Poshta 1.18.7 - 1.19.8 - Unauthenticated Order Shipment Record Deletion |
| CVE-2026-84220 | 4.8 MEDIUM | Kirki < 6.3.2 - Unauthenticated Arbitrary Shortcode Execution via Comments Collection |
| CVE-2026-85348 | 4.3 MEDIUM | GDPR Data Request Form 1.5 - 1.7.1 - DPO Email Update via CSRF |
| CVE-2026-84224 | 4.1 MEDIUM | Kirki < 6.3.2 - Editor+ Blind SSRF via Remote Template URL |
| CVE-2026-106095 | Code Snippets < 3.10.0 - Admin+ Network-Scoped Snippet Activation and Deactivation via upd | |
| CVE-2026-106097 | Code Snippets < 3.10.0 - Admin+ SQLi in Migration Importers Leading to Network-Wide Creden | |
| CVE-2026-93548 | FooSales < 1.43.3 - Subscriber+ Privilege Escalation via User Impersonation | |
| CVE-2026-87841 | UnitechPay <= 1.0.6.3 - Unauthenticated Order Payment Bypass via Unsigned Webhook | |
| CVE-2026-92990 | SendPress <= 1.26.1.20 - Unauthenticated Newsletter Sending Log Disclosure via Hardcoded T | |
| CVE-2026-88931 | Social Web Suite <= 4.1.12 - Unauthenticated Arbitrary Plugin Settings Update | |
| CVE-2026-86850 | SKU Error Fixer for WooCommerce <= 1.0 - Unauthenticated Orphaned Product Variation Deleti | |
| CVE-2025-15700 | AWP Classifieds < 4.4.9 - Admin+ Arbitrary File Upload via ZIP Import | |
| CVE-2026-92989 | SendPress Newsletters <= 1.26.1.20 - Subscriber+ Mailing List Sync and Newsletter Queueing |
No comments yet