Meow Gallery WordPress 插件在 5.5.5 版本之前,在返回文章数据之前,未进行适当的权限(capability)检查,也未将结果限制为请求用户自身的文章。这允许拥有 Author(作者)级别及以上权限的已认证用户,查看其他用户的草稿状态和私有文章的标题、作者、日期及状态信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Meow Gallery | 0 ~ 5.5.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84223 | Kirki 6.0.0 - 6.3.0 - Author+ Stored XSS via Unsanitized SVG Upload | |
| CVE-2026-14844 | Master Slider <= 3.11.2 - Contributor+ Stored XSS via ms_slider Shortcode Attributes | |
| CVE-2026-16542 | Import and export users and customers < 2.4.5 - Admin+ SSRF via bp_avatar | |
| CVE-2026-81650 | NextGEN Gallery < 4.5.0 - Authenticated Arbitrary File Upload via ZIP Import | |
| CVE-2026-81652 | NextGEN Gallery < 4.5.0 - Contributor+ Image Metadata Disclosure via IDOR | |
| CVE-2026-81653 | NextGEN Gallery < 4.5.0 - Authenticated Arbitrary Gallery Image Deletion via IDOR | |
| CVE-2026-81654 | NextGEN Gallery < 4.5.0 - Authenticated Plugin Image Settings Update | |
| CVE-2026-81651 | NextGEN Gallery < 4.5.0 - Authenticated Cross-Gallery Settings Modification via IDOR | |
| CVE-2026-87068 | Forminator Forms < 1.57.2.1 - Authenticated Privilege Escalation via Quiz Lead-Form Import | |
| CVE-2026-87067 | Forminator Forms < 1.57.2.1 - Authenticated RCE via XML-RPC PHP Object Injection | |
| CVE-2026-92540 | Import and export users and customers < 2.5.2 - Custom Role Privilege Escalation to Admini | |
| CVE-2026-85017 | Unlimited Elements For Elementor < 2.0.20 - Subscriber+ PHP Object Injection | |
| CVE-2026-82842 | SAML Single Sign On < 6.0.0 - Unauthenticated Privilege Escalation via Account Matching | |
| CVE-2026-87840 | Tripzzy < 1.5.1 - Unauthenticated Booking Data Tampering | |
| CVE-2026-87839 | Tripzzy < 1.5.1 - Unauthenticated Arbitrary Comment Deletion | |
| CVE-2026-92410 | Sign-up Sheets < 2.4.0 - Arbitrary Sign-up Deletion via CSRF | |
| CVE-2026-92422 | Meow Gallery < 5.5.5 - Unauthenticated Arbitrary Shortcode Execution via load_gallery_coll | |
| CVE-2026-92965 | TikTok 1.2.0 - 1.4.1 - Unauthenticated OAuth Code Redemption | |
| CVE-2026-92541 | Import and export users and customers < 2.5.2 - Custom Role Privilege Escalation to Admini |
No comments yet