Quads Ads Manager for Google AdSense WordPress 插件在 3.0.5 版本之前,在将广告销售订单标记为“已支付”之前,未向所配置的支付网关验证支付是否已完成。这使得能够下单的用户可以在未实际付款的情况下获得已支付的广告位。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Quads Ads Manager for Google AdSense | 3.0.4 ~ 3.0.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81648 | 10.0 CRITICAL | CryptoPayment Gateway 1.2.1 - 1.2.2 - Unauthenticated Arbitrary File Deletion and Settings |
| CVE-2026-74933 | 8.8 HIGH | GenieWords 1.5.27 - 1.5.34 - Unauthenticated Stored XSS and Configuration Overwrite |
| CVE-2026-85129 | 8.8 HIGH | Hoo Companion 1.0.2 - Unauthenticated Stored XSS via Theme Settings Import |
| CVE-2026-88793 | 8.8 HIGH | YouTube Embed 10.0 - 10.3 - Unauthenticated Stored XSS via youram_server |
| CVE-2026-88802 | 7.5 HIGH | MDJM Event Management and Mobile Events Manager - Unauthenticated Arbitrary Post Deletion |
| CVE-2026-77773 | Social Contact Form (FormyChat) < 2.15.8 - Unauthenticated Gravity Forms Entry Disclosure | |
| CVE-2026-86406 | User Registration & Membership < 5.2.8 - Subscriber+ Privilege Escalation via Membership P | |
| CVE-2026-80071 | User Registration & Membership < 5.2.8 - Author+ Privilege Escalation to Administrator | |
| CVE-2026-80072 | User Registration & Membership < 5.2.8 - Unauthenticated Open Redirect via Login Redirect | |
| CVE-2026-86407 | User Registration & Membership < 5.2.8 - Unauthenticated User Data Disclosure via Membersh | |
| CVE-2026-88764 | Simple Membership < 4.7.8 - Subscriber+ Membership Level Escalation via PayPal Standard su | |
| CVE-2026-88912 | rtMedia for WordPress, BuddyPress and bbPress < 4.7.12 - Subscriber+ Arbitrary Activity Pr | |
| CVE-2026-88995 | Bookit < 2.6.0.1 - Unauthenticated Appointment PII Disclosure via Availability Check | |
| CVE-2026-89080 | Really Simple Security < 9.8.1 - Unauthenticated 2FA Bypass via Email Provider State Demot |
No comments yet