WooCommerce WordPress 插件中的黑名单管理器(Blacklist Manager)在 1.3.0 到 2.3.1 版本中存在安全漏洞,该漏洞未能对所有的身份验证路径强制执行用户封锁机制。这意味着,即使网站管理员已经封禁了某个账户,该账户的持有者仍可以使用此账户以相应的权限进行身份验证,而不会受到封锁限制,且封锁行为不会被记录。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Blacklist Manager | 1.3.0 ~ 2.3.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84744 | 6.5 MEDIUM | WPForms Lite 1.5.0.1 - 2.0.2 - Unauthenticated Arbitrary Shortcode Execution via Form Fiel |
| CVE-2026-92996 | 5.3 MEDIUM | Verge3D 4.1.0 - 4.13.0 - Unauthenticated Payment Bypass via v3d_payment_done |
| CVE-2026-89411 | 5.3 MEDIUM | Paymattic < 4.6.26 - Unauthenticated Payment Bypass via Unbound Stripe PaymentIntent |
| CVE-2026-86838 | 5.3 MEDIUM | Bookly < 28.3 - Unauthenticated Payment Bypass via Booking Price Manipulation |
| CVE-2026-93000 | SPS-Suite <= 1.4.0 - Unauthenticated Time-Based SQLi via Search | |
| CVE-2026-89300 | WP Verify API <= 1.0.0 - Unauthenticated Verification Code Email Sending to Arbitrary Reci | |
| CVE-2026-89303 | Post Voting System <= 1.0 - Subscriber+ SQLi via 'row' Parameter |
No comments yet