| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | MainWP Child | < 6.1.2 | affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | MainWP Child | 0 ~ 6.1.2 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-13726 | Multiple Page Generator Plugin – MPG < 4.1.8 - Reflected XSS via mpg_shortcode | |
| CVE-2025-15662 | Printcart Web to Print Product Designer for WooCommerce < 2.5.3 - Unauthenticated Arbitrar | |
| CVE-2026-10082 | Advanced Ads – Ad Manager & AdSense < 2.0.23 - Contributor+ Stored XSS via the_ad Shortcod | |
| CVE-2026-13152 | Custom Fields Account Registration For WooCommerce < 1.4 - Unauthenticated Privilege Escal | |
| CVE-2026-12982 | Document Gallery < 5.1.1 - Reflected XSS via dg_generate_gallery | |
| CVE-2026-12394 | MemberGlut < 1.1.5 - Unauthenticated Privilege Escalation to Administrator | |
| CVE-2026-12493 | Clover Payment Gateway by Zaytech for WooCommerce < 1.3.6 - Unauthenticated Payment Bypass | |
| CVE-2026-13400 | Simply Schedule Appointments < 1.6.12.4 - Unauthenticated Stored XSS via Booking Customer | |
| CVE-2026-13332 | Masteriyo LMS < 2.3.1 - Unauthenticated Arbitrary User Session Termination (Denial of Serv | |
| CVE-2026-13390 | The Events Calendar < 6.16.5.1 - Unauthenticated Event Aggregator Import Status Manipulati | |
| CVE-2026-13597 | QRcode Login for WeChat <= 1.3 - Unauthenticated Account Takeover | |
| CVE-2026-9830 | BookingPress Pro < 5.7.3 - Unauthenticated Customer PII Disclosure and Booking Tampering v | |
| CVE-2026-13714 | Realtyna Organic IDX plugin + WPL Real Estate < 5.3.0 - Unauthenticated Arbitrary File Upl | |
| CVE-2026-14190 | Sina Extension for Elementor < 3.10.2 - Reflected XSS | |
| CVE-2026-14189 | WPBot AI ChatBot < 8.5.2 - Admin+ Second-Order SQL Injection via qc_bot_str_fields | |
| CVE-2026-14203 | Smart Manager < 8.92.0 - Contributor+ Stored XSS via Post Title | |
| CVE-2026-14568 | WP User Frontend < 4.3.8 - Unauthenticated Author-less Attachment Deletion | |
| CVE-2026-14236 | Contact Form 7 – PayPal & Stripe Add-on < 2.5 - Open Redirect | |
| CVE-2026-14289 | WP FacturaONE < 5.37 - Unauthenticated Remote Code Execution | |
| CVE-2026-14235 | WordPress Download Manager < 3.3.62 - Unauthorized Protected File Download via Reusable Do |
Showing top 20 of 23 CVEs. View all on vendor page → →
No comments yet