Liquid Web / StellarWP Advanced Post Manager(advanced-post-manager)中存在不信任数据反序列化漏洞,允许进行对象注入。该问题影响 Advanced Post Manager 的以下版本:从 n/a 到 4.5.5(含)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Liquid Web / StellarWP | Advanced Post Manager | ≤ 4.5.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Liquid Web / StellarWP | Advanced Post Manager | 0 ~ 4.5.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104404 | 6.5 MEDIUM | WordPress GiveWP plugin <= 4.17.0 - Cross Site Scripting (XSS) vulnerability |
| CVE-2026-104675 | 4.3 MEDIUM | WordPress Event Tickets plugin <= 5.30.0 - Broken Access Control vulnerability |
No comments yet