在 WPeMatico RSS Feed Fetcher WordPress 插件版本 2.8.26 之前,该插件在返回活动的存储配置和运行日志之前,未验证用户对该活动的所有权或授权。这使得具有贡献者(contributor)及以上权限的用户能够读取其他用户(包括管理员)创建的活动配置及执行日志。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WPeMatico RSS Feed Fetcher | 0 ~ 2.8.26 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93662 | Events Manager 7.4.1 - 7.4.4 - Subscriber+ Unpublished Event and Location Disclosure via ' | |
| CVE-2026-93661 | Events Manager < 7.4.5 - Contributor+ Arbitrary Ticket Overwrite via IDOR | |
| CVE-2026-88847 | MasterStudy LMS < 3.7.50 - Subscriber+ Lesson Completion Record Creation | |
| CVE-2026-89005 | WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Stored XSS via Word to Category | |
| CVE-2026-89002 | WPeMatico RSS Feed Fetcher < 2.8.26 - Contributor+ Stored XSS via Campaign Item Preview | |
| CVE-2026-88843 | MasterStudy LMS 3.5.29 - < 3.7.50 - Contributor+ LFI via Elementor Courses Categories Widg | |
| CVE-2026-88846 | MasterStudy LMS 2.3.0 - < 3.7.50 - Unauthenticated Account Creation with Registration Disa | |
| CVE-2026-88845 | MasterStudy LMS 2.3.0 - < 3.7.50 - Subscriber+ Course and Lesson Creation via Demo Import | |
| CVE-2026-82195 | 10Web Booster < 2.34.0 - Unauthenticated Connection Secret Disclosure and Deletion | |
| CVE-2026-82850 | Masteriyo LMS < 3.4.2 - Subscriber+ Quiz Answer Key Disclosure | |
| CVE-2026-82849 | Masteriyo LMS < 3.4.2 - Subscriber+ Arbitrary User Course Progress Disclosure via IDOR | |
| CVE-2026-84151 | The Post Grid < 7.9.5 - Contributor+ Stored HTML/iframe Injection via wp_kses_post Allow-L | |
| CVE-2026-74991 | WPForms Lite 1.8.8.2 - 2.0.1.1 - Unauthenticated Stripe Refund and Subscription Cancellati | |
| CVE-2026-80338 | CMB2 < 2.13.0 - Subscriber+ Arbitrary Option Corruption via oEmbed Handler | |
| CVE-2026-80513 | wpForo Forum < 3.1.6 - Subscriber+ PHP Object Injection via Profile Fields |
No comments yet