从 4.1.0 到 4.13.0 版本的 Verge3D WordPress 插件未向支付服务提供商验证支付是否实际完成,也未检查订单的所有权,导致未经认证的用户可以将任意订单标记为已支付。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Verge3D Publishing and E-Commerce | 4.1.0 ~ 4.13.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84744 | 6.5 MEDIUM | WPForms Lite 1.5.0.1 - 2.0.2 - Unauthenticated Arbitrary Shortcode Execution via Form Fiel |
| CVE-2026-88828 | 5.4 MEDIUM | Blacklist Manager for WooCommerce 1.3.0 - 2.3.1 - Blocked User Restriction Bypass via XML- |
| CVE-2026-89411 | 5.3 MEDIUM | Paymattic < 4.6.26 - Unauthenticated Payment Bypass via Unbound Stripe PaymentIntent |
| CVE-2026-86838 | 5.3 MEDIUM | Bookly < 28.3 - Unauthenticated Payment Bypass via Booking Price Manipulation |
| CVE-2026-93000 | SPS-Suite <= 1.4.0 - Unauthenticated Time-Based SQLi via Search | |
| CVE-2026-89300 | WP Verify API <= 1.0.0 - Unauthenticated Verification Code Email Sending to Arbitrary Reci | |
| CVE-2026-89303 | Post Voting System <= 1.0 - Subscriber+ SQLi via 'row' Parameter |
No comments yet