Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Unknown — Vulnerabilities & Security Advisories 4787

Browse all 4787 CVE security advisories affecting Unknown. AI-powered Chinese analysis, POCs, and references for each vulnerability.

“Unknown” represents a broad category of unclassified or poorly documented software components, currently associated with 4,141 recorded CVEs. These vulnerabilities typically stem from legacy architectures or proprietary systems lacking transparent security audits. Common flaw classes include remote code execution, cross-site scripting, and privilege escalation, often resulting from inadequate input validation or hardcoded credentials. Due to the opaque nature of these products, detailed security characteristics are frequently absent, making risk assessment difficult for organizations. Major incidents involving “Unknown” entities often highlight systemic failures in patch management and vendor accountability. The sheer volume of vulnerabilities suggests widespread reliance on unsupported or obscure technologies within critical infrastructure. Addressing these risks requires rigorous inventory management and proactive threat hunting, as standard mitigation strategies may not apply to such undefined software ecosystems.

CVE IDTitleCVSSSeverityPublished
CVE-2026-18044 Estatik Real Estate Plugin < 4.3.4 - Unauthenticated Arbitrary-Recipient Mail Relay via Signed-Value Mismatch — Estatik Real Estate Plugin 3.7 Low2026-08-12
CVE-2026-17008 Quick PayPal Payments <= 5.7.50 - Unauthenticated Payment Bypass via PayPal IPN — Quick Paypal Payments 5.3 Medium2026-08-12
CVE-2026-16990 Payment Button for PayPal <= 1.2.3.44 - Unauthenticated Payment Price Manipulation — Payment Button for PayPal 5.3 Medium2026-08-12
CVE-2026-16747 Kirki < 6.2.1 - Unauthenticated Arbitrary Shortcode Execution via Form Email Actions — Kirki 6.5 Medium2026-08-12
CVE-2026-15213 Welcart e-Commerce < 2.11.33 - Unauthenticated Payment Bypass via Forged Settlement Callback — Welcart e-Commerce 5.3 Medium2026-08-12
CVE-2026-16621 Payment Gateway for PayPal on WooCommerce < 9.2.1 - Unauthenticated Payment Bypass via PayPal Advanced Return Handler — Payment Gateway for PayPal on WooCommerce 5.3 Medium2026-08-12
CVE-2026-15045 Wallet System for WooCommerce < 2.7.10 - Customer+ Checkout Price Manipulation via Unvalidated Wallet Amount — Wallet System for WooCommerce 6.5 Medium2026-08-12
CVE-2026-19052 ProSolution WP Client < 2.0.9 - Subscriber+ proSol_ajaxTablesync and proSol_ajaxClearlog Calls — ProSolution WP Client--2026-08-12
CVE-2026-19073 Order Sync with Zendesk for WooCommerce < 2.2.3 - Unauthenticated Customer Order Data Disclosure — Order Sync with Zendesk for WooCommerce--2026-08-12
CVE-2026-19217 Royal Elementor Addons < 1.7.1065 - Contributor+ Stored XSS via Icon Box Widget — Royal Addons for Elementor--2026-08-12
CVE-2026-18943 WPC Admin Columns < 2.3.4 - Subscriber+ Arbitrary User/Post/Term Meta Disclosure — WPC Admin Columns--2026-08-12
CVE-2026-18789 Ezoic < 2.23.1 - Unauthenticated Database Export via Content Export REST Routes — Ezoic--2026-08-12
CVE-2026-18962 WP Photo Album Plus < 9.2.09.002 - Subscriber+ Cross-Album File Upload via Missing Authorization — WP Photo Album Plus--2026-08-12
CVE-2026-18474 WP Directory Kit < 1.5.6 - Unauthenticated SQL Injection via search_location and search_category — WP Directory Kit--2026-08-12
CVE-2026-19050 ProSolution WP Client < 2.0.9 - Subscriber+ SSRF via proSol_url_validate — ProSolution WP Client--2026-08-12
CVE-2026-18048 WP Photo Album Plus < 9.2.07.002 - Unauthenticated Arbitrary ZIP File Deletion via delmyzip Path Traversal — WP Photo Album Plus--2026-08-12
CVE-2026-18391 WooCommerce Subscriptions < 9.1.0 - Unauthenticated RCE via PHP Object Injection — WooCommerce Subscriptions--2026-08-12
CVE-2026-18230 WP Directory Kit < 1.5.6 - Subscriber+ SQL Injection via section Parameter — WP Directory Kit--2026-08-12
CVE-2026-18366 Events Manager < 7.4.1 - Unauthenticated Privilege Escalation to Administrator — Events Manager--2026-08-12
CVE-2026-18049 WP Photo Album Plus < 9.2.07.002 - Unauthenticated Option Disclosure via gettogo — WP Photo Album Plus--2026-08-12
CVE-2026-18057 Events Manager < 7.4.1 - Subscriber+ Booking Consent Record Tampering via SQL Injection — Events Manager--2026-08-12
CVE-2026-16977 Form Maker by 10Web < 1.15.45 - Subscriber+ SQL Injection via display_name — Form Maker by 10Web--2026-08-12
CVE-2026-16737 WP Travel Engine < 6.8.5 - Unauthenticated Booking Details Disclosure and Modification via wte_add_trip_to_cart — WP Travel Engine--2026-08-12
CVE-2026-18035 User Access Manager < 2.3.15 - Unauthenticated Restricted Content Disclosure via REST API — User Access Manager--2026-08-12
CVE-2026-18046 Cookie Consent < 0.0.10 - Subscriber+ MaxMind License Key Update — Cookie Consent--2026-08-12
CVE-2026-17013 WP Photo Album Plus < 9.2.07.002 - Reflected XSS via lbstart — WP Photo Album Plus--2026-08-12
CVE-2026-16051 WPMU DEV Dashboard < 5.0.1 - Remote Code Execution via Hub Install Action — wpmudev-updates--2026-08-12
CVE-2026-16294 Blubrry PowerPress < 11.17.1 - Contributor+ Server-Side Request Forgery via Podcast Episode Chapters URL — PowerPress Podcasting plugin by Blubrry--2026-08-12
CVE-2026-16253 Total Upkeep (BoldGrid Backup) < 1.17.3 - Unauthenticated Sensitive Data Disclosure and Forced Site Restore via Predictable cron_secret (regression of CVE-2020-36848) — Total Upkeep--2026-08-12
CVE-2026-16066 Welcart e-Commerce < 2.11.34 - Author+ Stored XSS via Product Name — Welcart e-Commerce--2026-08-12

This page lists every published CVE security advisory associated with Unknown. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.