CVE-2026-105571
A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function of the file /buyer/passport/member/bindM
CVSS
7.3
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Oct 6, 2026 · Last modified: Oct 6, 2026 · CWE-266 · CWE-285
Not enough EPSS history yet.
A flaw has been found in PickMall Lilishop up to 4.2.4. The impacted element is an unknown function of the file /buyer/passport/member/bindMobile of the component Mobile Binding. This manipulation of the argument Username causes improper authorization. It is possible to initiate the attack remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-955948.1 HIG—
———Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 4.0.0 versions.6hCVE-2026-481977.2 HIG—
———Incorrect Privilege Assignment vulnerability in PublishPress PublishPress Capabilities capability-manager-enhanced allows Privilege Escalation.This issue affects PublishPress Capabilities: from n/a through 2.45.0.6hCVE-2026-397758.8 HIG—
———Subscriber Privilege Escalation in JobZilla - Job Board WordPress Theme <= 2.2 versions.6hCVE-2026-397748.8 HIG—
———Unauthenticated Privilege Escalation in Tourfic Pro <= 1.17.3 versions.6hCVE-2026-3977310.0 CRI—
———Unauthenticated Privilege Escalation in Doctreat Core <= 1.7.0 versions.6hCVE-2026-397657.2 HIG—
———Shop Manager Privilege Escalation in Challan <= 3.7.88 versions.6h