MDJM Event Management WordPress 插件在 1.7.8.5 版本之前,以及 Mobile Events Manager WordPress 插件在 1.4.8.3 版本(含)之前,在通过请求永久删除其播放列表条目时,未校验用户权限(capability)、nonce 校验值以及记录类型。这使得未认证的攻击者可以绕过回收站,任意删除帖子、页面和媒体附件,从而造成内容永久丢失。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | MDJM Event Management | 0 ~ 1.7.8.5 | - |
|
| Unknown | Mobile Events Manager | 0 ~ 1.4.8.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81648 | 10.0 CRITICAL | CryptoPayment Gateway 1.2.1 - 1.2.2 - Unauthenticated Arbitrary File Deletion and Settings |
| CVE-2026-74933 | 8.8 HIGH | GenieWords 1.5.27 - 1.5.34 - Unauthenticated Stored XSS and Configuration Overwrite |
| CVE-2026-85129 | 8.8 HIGH | Hoo Companion 1.0.2 - Unauthenticated Stored XSS via Theme Settings Import |
| CVE-2026-88793 | 8.8 HIGH | YouTube Embed 10.0 - 10.3 - Unauthenticated Stored XSS via youram_server |
| CVE-2026-89050 | 4.3 MEDIUM | Quads Ads Manager for Google AdSense < 3.0.5 - Subscriber+ Ad-Selling Payment Bypass via U |
| CVE-2026-77773 | Social Contact Form (FormyChat) < 2.15.8 - Unauthenticated Gravity Forms Entry Disclosure | |
| CVE-2026-86406 | User Registration & Membership < 5.2.8 - Subscriber+ Privilege Escalation via Membership P | |
| CVE-2026-80071 | User Registration & Membership < 5.2.8 - Author+ Privilege Escalation to Administrator | |
| CVE-2026-80072 | User Registration & Membership < 5.2.8 - Unauthenticated Open Redirect via Login Redirect | |
| CVE-2026-86407 | User Registration & Membership < 5.2.8 - Unauthenticated User Data Disclosure via Membersh | |
| CVE-2026-88764 | Simple Membership < 4.7.8 - Subscriber+ Membership Level Escalation via PayPal Standard su | |
| CVE-2026-88912 | rtMedia for WordPress, BuddyPress and bbPress < 4.7.12 - Subscriber+ Arbitrary Activity Pr | |
| CVE-2026-88995 | Bookit < 2.6.0.1 - Unauthenticated Appointment PII Disclosure via Availability Check | |
| CVE-2026-89080 | Really Simple Security < 9.8.1 - Unauthenticated 2FA Bypass via Email Provider State Demot |
No comments yet