在 WordPress 多站点(multisite)环境中,User Private Files 插件(版本低于 2.2.0)未能妥善保护其存储的私有文件。该插件依赖于重写规则(rewrite rule)将文件请求路由至其访问检查逻辑,但在多站点安装中,该重写规则从未被触发,导致未认证用户可以绕过访问控制,直接获取其他用户的私有文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | User Private Files | 0 ~ 2.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93549 | CoCart 4.9.0 - 4.9.6 - Administrator Account Creation via REST API Authentication Bypass | |
| CVE-2026-86817 | Five Star Business Profile and Schema 2.3.20 - 2.3.21 - Author+ Sensitive Data Disclosure | |
| CVE-2026-17005 | Horizontal Scrolling Announcements <= 2.6 - Contributor+ Stored XSS via Style Field | |
| CVE-2026-104118 | Razorpay for WooCommerce < 4.8.8 - Unauthenticated Order Shipping Modification via IDOR | |
| CVE-2026-104119 | Simple Shopping Cart < 5.2.6 - Admin+ Stored XSS via PayPal API Credentials |
No comments yet