References http://202.112.51.190:8080/vuln/VHN-302397 https://blog.csdn.net/qq_51267159/article/details/122910501 https://www.cnblogs.com/0x28/p/14380432.html https://github.com/emadshanab/goby-poc/blob/main/WordPress-Plugin-Mailpress-4.5.2-RCE.json https://blog.csdn.net/ping_pig/article/details/102906932 https://www.acunetix.com/vulnerabilities/web/wordpress-plugin-mailpress-remote-code-execution-7-0-2/ https://www.invicti.com/web-application-vulnerabilities/wordpress-plugin-mailpress-remote-code-execution-7-0-2
Related VulnerabilitiesPoCCVE-2026-86242: Bifrost < 1.6.3 - Unauthenticated Remote Plugin URL Fetch中科商软云连ERP /admin/session!ajaxList.action 未授权访问漏洞ZKTeco-百傲瑞达安防管理系统平台 /authLicenseAction!getLicenseInfo.do 代码执行漏洞PoCCVE-2026-87902: WordPress Core - PHP Template Path TraversalPoCCVE-2026-80099: Newfold WordPress Plugins - Unauthenticated Admin Bypass via Empty HMAC SecretPoCCVE-2026-84434: WordPress Gravity Forms Plugin <=3.1.0.4 - Unauthenticated Arbitrary File UploadPoCwordpress-click2shell: WordPress Click2Shell Theme Preview Selector InjectionPoCCVE-2026-41948: Dify <=1.14.1 - Unauthenticated Plugin Daemon Path TraversalJeecgBoot 积木报表 /jmreport/auto/export/python/plugin 代码执行漏洞Wordpress Events Calendar插件敏感信息泄露漏洞(CVE-2025-9808)WordPress Directory Kit 插件敏感信息泄露漏洞(CVE-2025-13920)仁和兴业(深圳)软件有限公司仁和云ERP weChatAppletgetGoodsList.action 存在SSRF漏洞仁和兴业(深圳)软件有限公司仁和云ERP purchaseOrdersaveOrderApplet.action存在反序列化漏洞