SPS-Suite WordPress 插件(版本 1.4.0 及之前)在启用静态页面搜索功能时,未对搜索查询进行安全过滤就直接用于 SQL 查询,从而导致未经身份验证的攻击者可执行 SQL 注入攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84744 | 6.5 MEDIUM | WPForms Lite 1.5.0.1 - 2.0.2 - Unauthenticated Arbitrary Shortcode Execution via Form Fiel |
| CVE-2026-88828 | 5.4 MEDIUM | Blacklist Manager for WooCommerce 1.3.0 - 2.3.1 - Blocked User Restriction Bypass via XML- |
| CVE-2026-92996 | 5.3 MEDIUM | Verge3D 4.1.0 - 4.13.0 - Unauthenticated Payment Bypass via v3d_payment_done |
| CVE-2026-89411 | 5.3 MEDIUM | Paymattic < 4.6.26 - Unauthenticated Payment Bypass via Unbound Stripe PaymentIntent |
| CVE-2026-86838 | 5.3 MEDIUM | Bookly < 28.3 - Unauthenticated Payment Bypass via Booking Price Manipulation |
| CVE-2026-89300 | WP Verify API <= 1.0.0 - Unauthenticated Verification Code Email Sending to Arbitrary Reci | |
| CVE-2026-89303 | Post Voting System <= 1.0 - Subscriber+ SQLi via 'row' Parameter |
No comments yet