WordPress 插件 rtMedia for WordPress, BuddyPress and bbPress 在 4.7.12 之前版本中,在修改活动(activity)及其附带媒体的隐私级别时,未先检查所有权(ownership),仅依赖于每个登录用户共享的非ce(nonce),使得拥有 订阅者级别或更高权限的用户可以将其他用户的私人活动设为公开,或将其隐藏。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | rtMedia for WordPress, BuddyPress and bbPress | 0 ~ 4.7.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89080 | Really Simple Security < 9.8.1 - Unauthenticated 2FA Bypass via Email Provider State Demot | |
| CVE-2026-86407 | User Registration & Membership < 5.2.8 - Unauthenticated User Data Disclosure via Membersh | |
| CVE-2026-88764 | Simple Membership < 4.7.8 - Subscriber+ Membership Level Escalation via PayPal Standard su | |
| CVE-2026-88995 | Bookit < 2.6.0.1 - Unauthenticated Appointment PII Disclosure via Availability Check | |
| CVE-2026-77773 | Social Contact Form (FormyChat) < 2.15.8 - Unauthenticated Gravity Forms Entry Disclosure | |
| CVE-2026-86406 | User Registration & Membership < 5.2.8 - Subscriber+ Privilege Escalation via Membership P | |
| CVE-2026-80071 | User Registration & Membership < 5.2.8 - Author+ Privilege Escalation to Administrator | |
| CVE-2026-80072 | User Registration & Membership < 5.2.8 - Unauthenticated Open Redirect via Login Redirect |
No comments yet