WP Mobile Menu WordPress 插件在 2.9 版本之前未正确验证其设置导入过程中的 nonce(一次性令牌),因此攻击者可以利用管理员会话发起跨站请求,从而导入任意的 WP Mobile Menu 插件设置。随后,这些被导入的值会未经转义地输出给所有访客,导致存储型跨站脚本攻击(Stored XSS)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | WP Mobile Menu | 2.7.4< 2.9 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WP Mobile Menu | 2.7.4 ~ 2.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88797 | Vayu X < 1.0.6 - Subscriber+ Arbitrary WordPress.org Plugin Installation and Activation | |
| CVE-2026-100143 | FluentCart < 1.6.5 - Unauthenticated Guest Customer Account Takeover via Checkout Email | |
| CVE-2026-75824 | WP User Frontend 2.5.8 - 4.3.11 - Unauthenticated Account Creation with Registration Disab | |
| CVE-2026-75823 | WP User Frontend 3.5.29 - 4.3.11 - Unauthenticated Privilege Escalation via Registration R | |
| CVE-2026-82127 | Schema & Structured Data for WP & AMP < 1.67 - Editor+ Stored XSS via Taxonomy Term Fields | |
| CVE-2026-80333 | Solace Extra < 1.7.2 - Unauthenticated Non-Published Post Content Disclosure via Preview R | |
| CVE-2026-83560 | New User Approve 3.1.0 - 3.2.9 - Unauthenticated PII Disclosure via Zapier API Key Bypass | |
| CVE-2026-75873 | Zella Theme < 2.6.3 - Unauthenticated Arbitrary File Upload | |
| CVE-2026-86789 | Connections Business Directory <= 10.4.67 - Unauthenticated Non-Public Directory Entry Dis | |
| CVE-2026-85001 | EmbedPress 4.4.9 - 4.6.6 - Contributor+ Stored XSS via Elementor Widget showTitle Attribut | |
| CVE-2026-85415 | Audio Player Block 1.1.0 - 1.6.2 - Contributor+ Stored XSS via Audio Download URL | |
| CVE-2026-85576 | All in One Files Upload for WooCommerce < 2.0.17 - Subscriber+ Arbitrary Plugin Settings U | |
| CVE-2026-85573 | All in One Files Upload for WooCommerce 2.0.3 - 2.0.16 - Unauthenticated Stored XSS via SV | |
| CVE-2026-88791 | Safe Redirect Manager < 2.3.0 - Open Redirect via Wildcard Redirect Rules | |
| CVE-2026-94274 | YayReviews 1.0.4 - 1.4.0 - Unauthenticated Sensitive Data Disclosure via REST API | |
| CVE-2026-87777 | Hostinger Reach 1.0.6 - 1.8.2 - Contributor+ Stored XSS via formId Elementor Widget Attrib | |
| CVE-2026-89193 | Robin Image Optimizer 2.0.0 - 2.0.7 - Unauthenticated Stored XSS via WebP URL Delivery HTM | |
| CVE-2026-89190 | Robin Image Optimizer < 2.0.8 - Subscriber+ Plugin Settings Disclosure via fy_ajax | |
| CVE-2026-90953 | Image Optimizer by Elementor < 1.7.7 - Subscriber+ Attachment Metadata and Site Statistics | |
| CVE-2026-91072 | EWWW Image Optimizer < 8.8.0 - Admin+ WebP File Rename and Deletion via Unrestricted Path |
Showing top 20 of 28 CVEs. View all on vendor page → →
No comments yet