目標達成 すべての支援者に感謝 — 100%達成しました!

目標: 1000 CNY · 調達済み: 1336 CNY

100%

WP-buy 厂商漏洞列表 / CVE 中文分析 25

WP-buy 厂商相关 25 条 CVE 漏洞,含 AI 中文分析、POC、CVSS 评分与受影响产品。

wp-buy 是一款基于 WordPress 的电商插件,旨在为网站提供商品展示与在线交易功能。截至最新统计,该组件已收录 23 条 CVE,历史漏洞多集中于未授权访问、SQL 注入及跨站脚本攻击,反映出输入验证与权限控制方面的不足。部分高危漏洞允许攻击者远程执行代码或窃取敏感数据。建议用户及时更新版本并严格遵循最小权限原则,以缓解潜在的安全风险。

CVE IDタイトルCVSS深刻度公開日
CVE-2026-28175 WordPress Visitors Traffic Real Time Statistics plugin <= 8.11 - Cross Site Scripting (XSS) vulnerability — Visitors Traffic Real Time StatisticsCWE-79 7.1 High2026-08-13
CVE-2026-52702 WordPress SEO Redirection plugin <= 9.17 - Cross Site Scripting (XSS) vulnerability — SEO RedirectionCWE-79 7.1 High2026-06-15
CVE-2026-2936 Visitor Traffic Real Time Statistics <= 8.4 - Unauthenticated Stored Cross-Site Scripting — Visitor Traffic Real Time StatisticsCWE-79 7.2 High2026-04-04
CVE-2025-49284 WordPress WP Maintenance Mode & Site Under Construction plugin <= 4.3 - Cross Site Request Forgery (CSRF) Vulnerability — WP Maintenance Mode & Site Under ConstructionCWE-352 4.3 Medium2025-06-06
CVE-2025-32266 WordPress 404 Image Redirection (Replace Broken Images) plugin <= 1.4 - Cross Site Request Forgery (CSRF) vulnerability — 404 Image Redirection (Replace Broken Images)CWE-352 4.3 Medium2025-04-04
CVE-2025-31570 WordPress Related Posts Widget with Thumbnails plugin <= 1.2 - CSRF to Stored XSS vulnerability — Related Posts Widget with ThumbnailsCWE-352 7.1 High2025-03-31
CVE-2025-31569 WordPress wordpress related Posts with thumbnails plugin <= 3.0.0.1 - CSRF to Stored XSS vulnerability — wordpress related Posts with thumbnailsCWE-352 7.1 High2025-03-31
CVE-2023-47557 WordPress Visitor Traffic Real Time Statistics plugin <= 7.2 - Broken Access Control vulnerability — Visitors Traffic Real Time StatisticsCWE-862 4.3 Medium2025-01-02
CVE-2024-54234 WordPress Limit Login Attempts plugin <= 5.5 - SQL Injection vulnerability — Limit Login AttemptsCWE-89 9.3 Critical2024-12-13
CVE-2024-52421 WordPress WP Popup Window Maker plugin <= 2.0 - CSRF to Stored XSS vulnerability — WP Popup Window MakerCWE-352 7.1 High2024-11-19
CVE-2024-49306 WordPress WP Content Copy Protection & No Right Click plugin <= 3.5.9 - Cross Site Request Forgery (CSRF) vulnerability — WP Content Copy Protection & No Right ClickCWE-352 4.3 Medium2024-10-20
CVE-2022-4534 Limit Login Attempts (Spam Protection) <= 5.3 - IP Address Spoofing to Protection Mechanism Bypass — Limit Login Attempts (Spam Protection)CWE-348 5.3 Medium2024-10-08
CVE-2023-51484 WordPress Login as User or Customer plugin <= 3.8 - Unauthenticated Account Takeover vulnerability — Login as User or Customer (User Switching)CWE-287 9.8 Critical2024-04-25
CVE-2023-36678 WordPress WP Content Copy Protection & No Right Click Plugin <= 3.5.5 is vulnerable to Cross Site Scripting (XSS) — WP Content Copy Protection & No Right ClickCWE-79 5.9 Medium2023-08-05
CVE-2022-40695 WordPress SEO Redirection Plugin plugin <= 8.9 - Multiple Cross-Site Scripting (CSRF) vulnerabilities — SEO Redirection Plugin – 301 Redirect Manager (WordPress plugin)CWE-352 5.4 Medium2022-11-18
CVE-2022-38704 WordPress SEO Redirection plugin <= 8.9 - Cross-Site Request Forgery (CSRF) vulnerability — SEO Redirection Plugin – 301 Redirect Manager (WordPress plugin)CWE-352 5.4 Medium2022-09-23
CVE-2022-23983 WordPress WP Content Copy Protection & No Right Click plugin <= 3.4.4 - Cross-Site Request Forgery (CSRF) leads to Settings Update vulnerability — WP Content Copy Protection & No Right Click (WordPress plugin)CWE-352 4.3 Medium2022-02-21
CVE-2021-24195 Login as User or Customer (User Switching) < 1.9 - Arbitrary Plugin Installation/Activation via Low Privilege User — Login as User or Customer (User Switching)CWE-285 8.8 -2021-05-14
CVE-2021-24194 Login Protection - Limit Failed Login Attempts < 2.9 - Arbitrary Plugin Installation/Activation via Low Privilege User — Login Protection – Limit Failed Login AttemptsCWE-285 8.8 -2021-05-14
CVE-2021-24193 Visitor Traffic Real Time Statistics < 2.12 - Arbitrary Plugin Installation/Activation via Low Privilege User — Visitor Traffic Real Time StatisticsCWE-285 8.8 -2021-05-14
CVE-2021-24192 Tree Sitemap < 2.9 - Arbitrary Plugin Installation/Activation via Low Privilege User — Tree Sitemap (Pages, Posts & Categories list)CWE-285 8.8 -2021-05-14
CVE-2021-24191 WP Maintenance Mode & Site Under Construction < 1.8.2 - Arbitrary Plugin Installation/Activation via Low Privilege User — WP Maintenance Mode & Site Under ConstructionCWE-285 8.8 -2021-05-14
CVE-2021-24190 WooCommerce Conditional Marketing Mailer < 1.5.2 - Arbitrary Plugin Installation/Activation via Low Privilege User — WooCommerce Conditional Marketing MailerCWE-285 8.8 -2021-05-14
CVE-2021-24189 Captchinoo, Google recaptcha for admin login page < 2.4 - Arbitrary Plugin Installation/Activation via Low Privilege User — Captchinoo, Google recaptcha for admin login pageCWE-285 8.8 -2021-05-14
CVE-2021-24188 WP Content Copy Protection & No Right Click < 3.1.5 - Arbitrary Plugin Installation/Activation via Low Privilege User — WP Content Copy Protection & No Right ClickCWE-285 8.8 -2021-05-14

本页汇总了 WP-buy 厂商截至目前公开的全部 25 条 CVE 漏洞。每条漏洞均包含 CVSS 评分、CWE 弱点分类、受影响产品与参考链接,并附带 AI 生成的中文分析以便快速判断风险。