References http://202.112.51.190:8080/vuln/VHN-302397 https://blog.csdn.net/qq_51267159/article/details/122910501 https://www.cnblogs.com/0x28/p/14380432.html https://github.com/emadshanab/goby-poc/blob/main/WordPress-Plugin-Mailpress-4.5.2-RCE.json https://blog.csdn.net/ping_pig/article/details/102906932 https://www.acunetix.com/vulnerabilities/web/wordpress-plugin-mailpress-remote-code-execution-7-0-2/ https://www.invicti.com/web-application-vulnerabilities/wordpress-plugin-mailpress-remote-code-execution-7-0-2
Related VulnerabilitiesPoCCVE-2026-41948: Dify <=1.14.1 - Unauthenticated Plugin Daemon Path TraversalJeecgBoot 积木报表 /jmreport/auto/export/python/plugin 代码执行漏洞Wordpress Events Calendar插件敏感信息泄露漏洞(CVE-2025-9808)WordPress Directory Kit 插件敏感信息泄露漏洞(CVE-2025-13920)仁和兴业(深圳)软件有限公司仁和云ERP weChatAppletgetGoodsList.action 存在SSRF漏洞仁和兴业(深圳)软件有限公司仁和云ERP purchaseOrdersaveOrderApplet.action存在反序列化漏洞仁和兴业(深圳)软件有限公司仁和云ERP userresetPassword.action 存在任意账号密码重置漏洞PoCCVE-2025-14998: Branda WordPress plugin - Privilege EscalationPoCCVE-2022-1281: Photo Gallery WordPress v1.6.3 - SQL InjectionPoCCVE-2026-12394: WordPress MemberGlut < 1.1.5 - Unauthenticated Privilege EscalationitC 中心管理服务器actionDetailTmpFile.do 存在任意文件上传漏洞PoCCVE-2026-55224: MineAdmin < 3.2.0-alpha.2 - Plugin Path Traversal to RCEPoCCVE-2019-1003030: Jenkins Pipeline Groovy Plugin <=2.63 - Insecure Deserialization