在 Premium Packages WordPress 插件 7.2.1 之前的版本中,该插件在处理支付和订阅通知时,并未验证 PayPal 的 Webhook 签名。这一漏洞允许未经身份验证的攻击者伪造支付确认和订阅取消事件,针对任何其已知交易 ID 的订单进行操作。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Premium Packages | 7.0.0< 7.2.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Premium Packages | 7.0.0 ~ 7.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86601 | 6.5 MEDIUM | WP Recipe Maker < 10.8.2 - Unauthenticated Arbitrary Shortcode Execution via Comment Conte |
| CVE-2026-86612 | 5.6 MEDIUM | Ninja Tables < 5.2.17 - Unauthenticated Arbitrary Shortcode Execution via Fluent Forms Dat |
| CVE-2026-84091 | 5.3 MEDIUM | SUMIT Payment Gateway for WooCommerce < 4.0.0 - Unauthenticated Payment Confirmation Forge |
| CVE-2026-90950 | 5.3 MEDIUM | Paid Member Subscriptions < 3.1.0 - Unauthenticated reCAPTCHA Bypass via Registration Form |
| CVE-2026-87978 | 5.3 MEDIUM | Paymob for WooCommerce < 4.1.14 - Unauthenticated Payment Bypass via Unverified Subscripti |
| CVE-2026-87071 | 5.3 MEDIUM | Forminator Forms < 1.57.2.1 - Unauthenticated Post Meta Injection on Submitted Posts |
| CVE-2026-87070 | 5.3 MEDIUM | Forminator Forms < 1.57.2.1 - Unauthenticated Poll Vote Limit Bypass via IP Spoofing |
| CVE-2026-86604 | 4.8 MEDIUM | GTranslate < 5.0.1 - Unauthenticated Arbitrary Shortcode Execution via Email Translation |
| CVE-2026-87848 | 3.7 LOW | MPCX Lightbox 1.2.2 - 1.2.5 - Unauthenticated Non-Public Post Content Disclosure |
| CVE-2026-93528 | NP Quote Request for WooCommerce < 2.4.16 - Unauthenticated Order Data Disclosure via Quot | |
| CVE-2026-86842 | Real3D Flipbook Lite < 5.4 - Author+ Content Deletion and Stored XSS via Global Settings O | |
| CVE-2026-91024 | Booking Manager < 2.1.21 - Author+ SQLi via ICS Import Feed UID (sync_gid) | |
| CVE-2026-89331 | FluentBoards 1.95 - 2.0.15 - Unauthenticated Board Member Email Address Disclosure via Pub | |
| CVE-2026-88997 | JSM Show Post Metadata < 4.9.1 - Contributor+ Stored XSS via Custom Field Meta Key | |
| CVE-2026-87981 | Paymob for WooCommerce < 4.1.14 - Contributor+ Payment Gateway Configuration Deletion and | |
| CVE-2026-87074 | Forminator Forms < 1.57.2.1 - Unauthenticated Arbitrary Recipient Email Sending with Attac | |
| CVE-2026-87979 | Paymob for WooCommerce < 4.1.14 - Unauthenticated Saved Card Token Write to Any User via W | |
| CVE-2026-88929 | Sale Booster 7.0.0 - 7.5.1 - Unauthenticated Non-Public Product Disclosure | |
| CVE-2026-87069 | Forminator Forms < 1.57.2.1 - Subscriber+ Form Stripe Field Migration via migrate_stripe | |
| CVE-2026-86783 | PostX < 5.0.41 - Unauthenticated Custom Field Key Disclosure via REST API |
Showing top 20 of 57 CVEs. View all on vendor page → →
No comments yet