Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Hoangphuong

#21493of 56,331
12.8Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2026-82872
5.3
2026-08-28
WordPress · Shared-Files-Pro · CVE-2026-12514
**Name of the Vulnerable Software and Affected Versions** Shared Files versions prior to 1.7.67 shared-files-pro versions prior to 1.7.70 **Description** The file-upload handler is registered for unauthenticated users and lacks a capability check, relying solely on a nonce output on public pages. This allows an unauthenticated visitor to upload files to a publicly accessible directory and retrieve the server's absolute path from the response. File uploads are restricted to WordPress's allowed MIME types, preventing the upload of executable PHP files. **Recommendations** Update Shared Files to version 1.7.67 or later. Update shared-files-pro to version 1.7.70 or later.
PT-2026-68634
7.5
2026-08-06
WordPress · Cocart · CVE-2026-10524
**Name of the Vulnerable Software and Affected Versions** CoCart WordPress plugin versions prior to 4.9.0 **Description** An issue exists where the software fails to validate user-supplied price values against the actual product price when items are added to the cart via public REST API endpoints. This allows unauthenticated users to set arbitrary prices for products and complete WooCommerce orders with manipulated totals. **Recommendations** Update CoCart WordPress plugin to version 4.9.0 or later.