WooCommerce 的“Track Orders”WordPress 插件在 1.2.7 版本之前存在安全漏洞:该插件在返回订单的账单详细信息时,未对订单所有权进行验证。攻击者无需认证即可通过提供客户电子邮件地址,获取该客户的姓名、电子邮件地址、电话号码、邮政地址以及订单历史记录。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Track Orders for WooCommerce | 0 ~ 1.2.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93509 | 6.5 MEDIUM | Wallet System for WooCommerce 2.0.0 - 2.7.10 - Subscriber+ Wallet Balance Manipulation via |
| CVE-2026-103517 | 5.3 MEDIUM | Airwallex Online Payments Gateway < 1.36.0 - Unauthenticated Payment Bypass via Forged Web |
| CVE-2026-104671 | 5.3 MEDIUM | TutorStarter < 4.0.4 - Unauthenticated User Registration Bypass via AJAX |
| CVE-2026-105190 | 5.3 MEDIUM | Easy Digital Downloads < 3.7.1 - Unauthenticated Account Creation with Registration Disabl |
| CVE-2026-103309 | GPTranslate < 2.34.14 - Unauthenticated Stored XSS via REST API Translation Storage | |
| CVE-2026-103646 | Ultimate Multisite < 2.17.0 - Unauthenticated Authentication Bypass via 'email_address' Pa | |
| CVE-2026-104646 | Image Photo Gallery Final Tiles Grid < 3.6.14 - Contributor+ Stored XSS via Gallery Shortc | |
| CVE-2026-104645 | Image Photo Gallery Final Tiles Grid < 3.6.14 - Contributor+ Arbitrary Gallery Cloning, Im | |
| CVE-2026-103692 | Frontend Dashboard 3.0.0 - 3.0.4 - Unauthenticated Privilege Escalation via Arbitrary Func | |
| CVE-2026-105195 | Booking Calendar 10.15 - 11.8.2 - Editor+ Arbitrary Option Disclosure | |
| CVE-2026-105197 | LatePoint < 5.6.5 - Agent+ Arbitrary Order, Customer and Transaction Deletion via IDOR | |
| CVE-2026-105198 | LatePoint < 5.7.3 - Unauthenticated Customer PII Disclosure via IDOR | |
| CVE-2026-105194 | Easy Digital Downloads < 3.7.1 - Subscriber+ Sensitive Information Disclosure via User Dow | |
| CVE-2026-105196 | LatePoint < 5.6.9 - Agent+ Cross-Agent Data Disclosure and Modification via Abilities API | |
| CVE-2026-105193 | Booking Calendar < 11.8 - Unauthenticated Booking Information Disclosure and Modification | |
| CVE-2026-86826 | BackWPup < 5.7.7 - Unauthenticated Sensitive Data Disclosure via Restore Working Directory | |
| CVE-2026-86827 | BackWPup 3.3 - 5.7.6 - Unauthenticated Backup Job Execution via wp-cron.php | |
| CVE-2026-86828 | BackWPup < 5.7.7 - Admin+ Path Traversal to RCE via Restore PclZip Fallback | |
| CVE-2026-105260 | Database Addon For WPForms < 1.1.1 - Arbitrary Form Entry Deletion via CSRF | |
| CVE-2026-94246 | Wallet System for WooCommerce 2.0.0 - 2.7.10 - Subscriber+ Forged Wallet Withdrawal Reques |
Showing top 20 of 24 CVEs. View all on vendor page → →
No comments yet