References https://www.twcert.org.tw/tw/cp-132-8136-4d5b4-1.html https://wellstsai.com/post/cve-2024-9970/ https://www.twcert.org.tw/newepaper/cp-151-8136-4d5b4-3.html https://nvd.nist.gov/vuln/detail/CVE-2024-9970 https://wellstsai.com/en/post/cve-2024-9970/ https://cc.nchu.edu.tw/p/404-1000-1425.php?Lang=zh-tw https://github.com/advisories/GHSA-7g9c-pfqm-8rrr https://vuldb.com/vuln/280328 https://www.newtype.com.tw/flowmasterbpm.aspx
Related VulnerabilitiesPoCCVE-2026-7467: Read More & Accordion <= 3.5.7 - Authenticated Privilege EscalationPoCCVE-2025-14998: Branda WordPress plugin - Privilege EscalationPoCCVE-2025-15403: RegistrationMagic <= 6.0.7.1 - Privilege EscalationPoCCVE-2026-11387: SMS Alert – SMS & OTP for WooCommerce - Privilege EscalationPoCCVE-2026-19598: Pods <= 3.3.9 - Unauthenticated Privilege Escalation via pods_admin AJAX RouterPoCCVE-2026-12394: WordPress MemberGlut < 1.1.5 - Unauthenticated Privilege EscalationPoCCVE-2026-17594: Sonatype Nexus Repository < 3.95.0 - Privilege Escalation via Repository Format MismatchPoCCVE-2024-57726: SimpleHelp <= 5.5.7 - Privilege EscalationPoCCVE-2026-27542: WooCommerce Wholesale Lead Capture <= 2.0.3.1 - Unauthenticated Privilege EscalationPoCCVE-2026-1492: WordPress User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation九佳易管理系统 PrivilegedCodeDestroy SQL注入漏洞九佳易 Interface/licx/PrivilegedCodeDestroy.asmx/UpdatePrivilegedState SQL 注入漏洞