References https://nvd.nist.gov/vuln/detail/CVE-2025-4602 https://ryankozak.com/posts/cve-2025-4602/ https://github.com/d0n601/CVE-2025-4602 https://cve.imfht.com/detail/CVE-2025-4602 https://avd.aliyun.com/detail?id=AVD-2025-4602 https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/store-manager-connector https://feedly.com/cve/CVE-2025-4602 https://cve.imfht.com/poc_detail/3009f048521246dc16baa40f587d86961cf56425 https://www.nsfocus.net/vulndb/121550 https://github.com/d0n601/CVE-2025-4602/blob/master/CVE-2025-4602.py
Related VulnerabilitiesPoCCVE-2026-0702: VidShop for WooCommerce <= 1.1.4 - SQL Injection旭辰資訊|SmartIT Desktop Manager - 存在4個漏洞中成科信票务管理系统 /SystemManager/TicketSystem/ReturnTicketPlance.ashx SQL 注入漏洞中成科信票务管理系统 /SystemManager/Planetarium/ReserveTicketManagerPlane.ashx SQL 注入漏洞PoCCVE-2026-65761: Joomla Easy Store - SQL InjectionPoCCVE-2026-11387: SMS Alert – SMS & OTP for WooCommerce - Privilege EscalationHepta Platforms|Heptabase - Stored Cross-Site ScriptingPoCCVE-2020-10204: Sonatype Nexus Repository Manager 3 - Remote Code ExecutionPoCCVE-2026-1115: parisneo/lollms < 2.2.0 - Authenticated Stored XSSPoCccm-detect: Clear-Com Core Configuration Manager Panel - DetectPoCds-store-file: DS_Store File - Exposed智慧物联网综合服务平台ListFileManager存在目录枚举漏洞PoCCVE-2026-27542: WooCommerce Wholesale Lead Capture <= 2.0.3.1 - Unauthenticated Privilege Escalation