Motors WordPress 插件在 1.4.124 版本之前存在一个漏洞,该漏洞未能正确验证用户是否具有修改特定列表的权限,便直接处理其列表管理操作。这使得具有订阅者级及以上权限的攻击者可以修改其并不拥有的帖子上的元数据,包括覆盖产品价格。利用此漏洞的前提条件是必须激活 WooCommerce 插件,并且启用 Motors WordPress 插件中付费 featured-listing 功能,这两种配置在默认情况下并未启用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-19856 | 6.5 MEDIUM | All in One SEO < 5.0.2.1 - Unauthenticated Arbitrary Shortcode Execution via Search Query |
| CVE-2026-84740 | 6.5 MEDIUM | The Events Calendar 6.12.0 - 6.17.5 - Unauthenticated Arbitrary Shortcode Execution via 'v |
| CVE-2026-92924 | 5.4 MEDIUM | Unlimited Elements For Elementor < 2.0.21 - Subscriber+ Arbitrary Shortcode Execution via |
| CVE-2026-85005 | 5.4 MEDIUM | Popup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invocation via Mis |
| CVE-2026-13413 | 5.3 MEDIUM | CMP - Coming Soon & Maintenance < 4.1.20 - Unauthenticated Maintenance Mode Bypass via Log |
| CVE-2026-90952 | 5.3 MEDIUM | WP Edit Password Protected 2.0.0 - 2.0.6 - Unauthenticated Site-Wide Access Mode Bypass vi |
| CVE-2026-90987 | 5.3 MEDIUM | Easy PayPal & Stripe Buy Now Button 1.8 - 2.0.5 - Unauthenticated Payment Amount Manipulat |
| CVE-2026-91020 | 5.3 MEDIUM | WebToffee Gift Cards for WooCommerce < 1.3.1 - Unauthenticated Gift Card Amount Manipulati |
| CVE-2026-79618 | 4.3 MEDIUM | WP User Frontend < 4.3.12 - Subscriber+ Post Creation via Subscription-Gated Form |
| CVE-2026-1661 | 4.3 MEDIUM | WP Mail Logging < 1.17.0 - Unauthenticated HTML Injection |
| CVE-2026-97219 | 4.3 MEDIUM | MStore API 4.21.1 - 4.22.0 - Subscriber+ Payment Bypass via 'status' Parameter |
| CVE-2026-97317 | Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated reCAPTCHA Secret Key Dis | |
| CVE-2026-97318 | Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated Stored Open Redirect via | |
| CVE-2026-94298 | BuildKit < 1.0.29 - Contributor+ Stored SQLi via list_content Parameter | |
| CVE-2026-91022 | Motors < 1.4.124 - Listing Manager+ Stored XSS via Badge Color | |
| CVE-2026-13718 | Tabs Responsive <= 2.5 - Shop Manager+ Stored XSS via WooCommerce Product Tab Content | |
| CVE-2026-85016 | Unlimited Elements For Elementor < 2.0.21 - Contributor+ Stored XSS via Icon Library Param | |
| CVE-2026-90988 | Request a Quote <= 2.5.6 - Unauthenticated Quote Request Contact Record Disclosure via emd | |
| CVE-2026-91828 | OMGF < 6.3.11 - Unauthenticated DoS via do_optimize | |
| CVE-2026-85004 | Popup Maker WP <= 1.4.5 - Subscriber+ Missing Authorization via sgpm_connect |
Showing top 20 of 22 CVEs. View all on vendor page → →
No comments yet