All 4 CVE vulnerabilities found in Verge3D Publishing and E-Commerce, with AI-generated Chinese analysis, references, and POCs.
Vendor: Soft8Soft LLC
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-92996 | Verge3D 4.1.0 - 4.13.0 - Unauthenticated Payment Bypass via v3d_payment_done | 5.3 | Medium | 2026-09-28 |
| CVE-2026-92995 | Verge3D <= 4.13.0 - Unauthenticated Product Download Disclosure via v3d_download_file | - | - | 2026-09-27 |
| CVE-2023-51421 | WordPress Verge3D Plugin <= 4.5.2 is vulnerable to Arbitrary File Upload CWE-434 | 9.9 | Critical | 2023-12-29 |
| CVE-2023-51420 | WordPress Verge3D Plugin <= 4.5.2 is vulnerable to Remote Code Execution (RCE) CWE-94 | 9.1 | Critical | 2023-12-29 |
All 4 known CVE vulnerabilities affecting Verge3D Publishing and E-Commerce with full Chinese analysis, references, and POCs where available.