在 WP Verify API WordPress 插件(版本 1.0.0 及之前)中,其某个 REST API 路由缺乏任何身份验证机制,导致未认证的用户可以向该插件自身的数据库表中插入任意数据,并能够使站点向任意电子邮件地址发送模板化的验证邮件。此外,该路由也未进行速率限制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WP Verify API | 0 ~ 1.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84744 | 6.5 MEDIUM | WPForms Lite 1.5.0.1 - 2.0.2 - Unauthenticated Arbitrary Shortcode Execution via Form Fiel |
| CVE-2026-88828 | 5.4 MEDIUM | Blacklist Manager for WooCommerce 1.3.0 - 2.3.1 - Blocked User Restriction Bypass via XML- |
| CVE-2026-92996 | 5.3 MEDIUM | Verge3D 4.1.0 - 4.13.0 - Unauthenticated Payment Bypass via v3d_payment_done |
| CVE-2026-89411 | 5.3 MEDIUM | Paymattic < 4.6.26 - Unauthenticated Payment Bypass via Unbound Stripe PaymentIntent |
| CVE-2026-86838 | 5.3 MEDIUM | Bookly < 28.3 - Unauthenticated Payment Bypass via Booking Price Manipulation |
| CVE-2026-93000 | SPS-Suite <= 1.4.0 - Unauthenticated Time-Based SQLi via Search | |
| CVE-2026-89303 | Post Voting System <= 1.0 - Subscriber+ SQLi via 'row' Parameter |
No comments yet