CVE-2026-71625: Slimkit plus ThinkSNS+ vulnerability
Published Sep 4, 2026
·Updated
An issue in slimkit plus ThinkSNS+ v.2.4 allows a remote attacker to escalate privileges via the ResetPasswordController.php component
Affected Software
1 affected component
slimkit plus ThinkSNS+=2.4
Event History
Sep 4, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which deployments are explicitly identified as affected?
The affected product and version identified are slimkit plus ThinkSNS+ version 2.4.
2
Is exploitation limited to attackers with local access?
No. The issue is described as allowing a remote attacker to escalate privileges through the ResetPasswordController.php component.