CoCart WordPress 插件在 4.9.7 版本之前,其 REST API 身份验证过滤器未正确限定在其自身接口上,导致禁用了 WordPress 核心对所有路由的 REST nonce 保护机制。攻击者可利用此漏洞,通过跨站请求伪造(CSRF)攻击,在已登录管理员会话的基础上创建新的管理员账户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-97332 | User Private Files < 2.2.0 - Unauthenticated Private File Disclosure via .htaccess Rewrite | |
| CVE-2026-86817 | Five Star Business Profile and Schema 2.3.20 - 2.3.21 - Author+ Sensitive Data Disclosure | |
| CVE-2026-17005 | Horizontal Scrolling Announcements <= 2.6 - Contributor+ Stored XSS via Style Field | |
| CVE-2026-104118 | Razorpay for WooCommerce < 4.8.8 - Unauthenticated Order Shipping Modification via IDOR | |
| CVE-2026-104119 | Simple Shopping Cart < 5.2.6 - Admin+ Stored XSS via PayPal API Credentials |
No comments yet