Hubtel WordPress 插件在 1.0.2 版本之前,未验证请求者是否有权查看订单,便在重定向公共支付回调请求时直接执行该操作。这使得未经身份验证的攻击者能够获取任意订单的订单密钥,并查看其内容。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Payments for Hubtel | 0 ~ 1.0.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-96200 | Payments for Hubtel < 1.0.2 - Unauthenticated Payment Confirmation Forgery via Delayed Pay | |
| CVE-2026-96255 | Payments for Hubtel < 1.0.2 - Unauthenticated Payment Gateway Credentials Disclosure via D | |
| CVE-2026-89296 | Pro Like Button < 2.0 - Unauthenticated SQLi via 'postid' Parameter | |
| CVE-2026-87973 | If-So Dynamic Content 1.9.9 - 1.10.1 - Editor+ Stored XSS via Conversion Name | |
| CVE-2026-87970 | If-So Dynamic Content 1.8 - 1.10.1 - Reflected XSS via render_ifso_shortcodes | |
| CVE-2026-92412 | Five Star Restaurant Reviews < 2.3.14 - Reflected XSS | |
| CVE-2026-90972 | WP Fusion Lite < 3.48.0 - Subscriber+ User Email Disclosure and Cross-User CRM Data Deleti | |
| CVE-2026-90974 | WP Fusion Lite 3.37.14 - 3.47.14 - Unauthenticated CRM Integration Settings Update | |
| CVE-2026-19253 | Cache Enabler < 1.8.17 - Unauthenticated Arbitrary File and Directory Deletion via cache_e | |
| CVE-2026-81739 | Paytm Payment Gateway < 2.8.9 - Unauthenticated Stored XSS via Payment Callback | |
| CVE-2026-81809 | Paytm Payment Gateway < 2.8.9 - Unauthenticated SQLi via Payment Callback | |
| CVE-2026-86610 | Download Manager < 3.3.71 - Author+ Stored XSS via Package Icon | |
| CVE-2026-101148 | BackupSheep <= 1.8 - Unauthenticated Arbitrary File Deletion and Backup Exfiltration via E | |
| CVE-2026-101147 | Featured Image from URL (FIFU) Free & Premium - Administrator Account Creation via CSRF |
No comments yet