版本 2.5.4 之前的 Comments Import & Export WordPress 插件在导出评论时存在安全漏洞:该插件未将评论导出功能限制在具备“审核评论”权限的用户,也未将导出范围限定为请求用户所拥有的内容。这导致拥有“作者(Author)”或更高权限的用户能够获取网站上的所有评论数据,包括评论者的电子邮件地址、IP 地址、未审批评论的内容以及评论元数据(comment meta)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Comments Import & Export | 2.1.11 ~ 2.5.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86801 | 8.8 HIGH | To Do List Member 1.4 - 1.6 - Unauthenticated Stored XSS, File Listing and Deletion via Un |
| CVE-2026-87963 | 8.6 HIGH | Yo 1.1 - 1.3.1 - Unauthenticated SQL Injection via username Parameter |
| CVE-2026-87829 | 4.3 MEDIUM | Checkout Field Manager < 7.9.7 - Subscriber+ Arbitrary Attachment Deletion via Unvalidated |
| CVE-2026-87831 | 4.3 MEDIUM | Checkout Field Manager < 7.9.7 - Subscriber+ Arbitrary Attachment Deletion via Customer Ad |
| CVE-2026-91017 | 3.7 LOW | Robokassa payment gateway for Woocommerce < 1.8.9 - Unauthenticated Payment Bypass via For |
| CVE-2025-15697 | Dictionary <= 1.0 - Reflected XSS via Multiple Parameters | |
| CVE-2026-85128 | Choose User Role at Registration for WooCommerce < 1.3.3 - Unauthenticated Privilege Escal | |
| CVE-2026-85130 | WPLP Cookie Consent < 4.4.4 - Unauthenticated Stored XSS via Consent Logs | |
| CVE-2026-86707 | Private Feed Key <= 0.1 - Unauthenticated Authentication Bypass via 'feedkey' Parameter | |
| CVE-2026-86709 | The Pressengine <= 1.0 - Unauthenticated Authentication Bypass | |
| CVE-2026-86710 | Login with QR <= 1.0.0 - Unauthenticated Authentication Bypass via 'autologin_code' Parame | |
| CVE-2026-86446 | LearnPress 4.4.3 - 4.4.6 - Unauthenticated Quiz Answer Disclosure via check-answer REST En | |
| CVE-2026-87786 | Dewa Kirim <= 1.0.0 - Unauthenticated Stored XSS via Checkout Coordinates | |
| CVE-2026-86824 | Newsletter < 9.3.8 - Unauthenticated Subscriber PII Disclosure and Modification via Predic | |
| CVE-2026-86788 | HT Mega 3.2.0 - 3.2.5 - Contributor+ Stored XSS via Section Headline Tag | |
| CVE-2026-90922 | Paid Member Subscriptions < 3.0.9 - Unauthenticated Membership Payment Bypass via PayPal S | |
| CVE-2026-88792 | Dictionary <= 1.0 - Unauthenticated Stored XSS via Direct Dictionary Update | |
| CVE-2026-88795 | wpShopGermany IT-RECHT KANZLEI < 2.4 - Unauthenticated RCE via Predictable API Token | |
| CVE-2026-88904 | PuppyFW <= 0.4.4 - Subscriber+ Arbitrary Blog Options Update and Deletion Leading to Privi | |
| CVE-2026-90923 | Autopay < 5.0.1 - Unauthenticated Cross-Customer Order Payment Parameter Disclosure and De |
Showing top 20 of 29 CVEs. View all on vendor page → →
No comments yet