Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

inc2734 — Vulnerabilities & Security Advisories 10

Browse all 10 CVE security advisories affecting inc2734. AI-powered Chinese analysis, POCs, and references for each vulnerability.

inc2734 is primarily associated with WordPress themes and plugins, serving as a core component for numerous business websites. Historically, the project has been vulnerable to multiple security issues, including cross-site scripting (XSS), remote code execution (RCE), and privilege escalation vulnerabilities. These weaknesses have allowed attackers to compromise websites, steal data, and gain unauthorized access. While no major public incidents have been widely documented, the consistent pattern of vulnerabilities across multiple CVEs highlights ongoing security challenges. The project's widespread adoption makes it a persistent target for exploitation, requiring vigilant maintenance and prompt patching by users to mitigate potential risks.

CVE ID Title CVSS Severity Published
CVE-2026-2594 Smart Custom Fields <= 5.0.7 - Authenticated (Author+) Stored Cross-Site Scripting via Attachment Title — Smart Custom Fields CWE-79 6.4 Medium 2026-07-17
CVE-2026-3004 Snow Monkey Blocks <= 24.1.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'data-slick' Attribute — Snow Monkey Blocks CWE-79 6.4 Medium 2026-05-13
CVE-2026-5436 MW WP Form <= 5.1.1 - Unauthenticated Arbitrary File Move via regenerate_upload_file_keys — MW WP Form CWE-22 8.1 High 2026-04-08
CVE-2026-4347 MW WP Form <= 5.1.0 - Unauthenticated Arbitrary File Move via move_temp_file_to_upload_dir — MW WP Form CWE-22 8.1 High 2026-04-02
CVE-2026-4066 Smart Custom Fields <= 5.0.6 - Missing Authorization to Authenticated (Contributor+) Sensitive Information Exposure via Relational Post Search — Smart Custom Fields CWE-862 4.3 Medium 2026-03-23
CVE-2026-1056 Snow Monkey Forms <= 12.0.3 - Unauthenticated Arbitrary File Deletion via Path Traversal — Snow Monkey Forms CWE-22 9.8 Critical 2026-01-28
CVE-2025-10137 Snow Monkey <= 29.1.5 - Unauthenticated Blind Server-Side Request Forgery — Snow Monkey CWE-918 5.4 Medium 2025-09-26
CVE-2024-1995 Smart Custom Fields <= 4.2.2 - Missing Authorization to Authenticated (Subscriber+) Post Content Disclosure — Smart Custom Fields CWE-862 4.3 Medium 2024-03-20
CVE-2023-6316 MW WP Form <= 5.0.1 - Unauthenticated Arbitrary File Upload — MW WP Form CWE-434 9.8 Critical 2024-01-11
CVE-2023-6559 MW WP Form <= 5.0.3 - Improper Limitation of File Name to Unauthenticated Arbitrary File Deletion — MW WP Form CWE-22 7.5 High 2023-12-16

This page lists every published CVE security advisory associated with inc2734. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.