PatchSiren

Brainstorm Force CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Brainstorm Force CVE published 2026-10-05

CVE-2026-39721

A Missing Authorization vulnerability exists in Brainstorm Force Starter Templates, affecting versions from n/a through 4.7.7. This issue allows for Exploiting Incorrectly Configured Access Control Security Levels. The CVSS score is 5.4, with a severity of MEDIUM. Defenders and administrators should assess exposure and prioritize updates to mitigate potential risks. Verification of plugin versions, assess [truncated]

MEDIUM Brainstorm Force CVE published 2026-10-05

CVE-2026-102914

A Cross-site Scripting (XSS) vulnerability exists in Presto Player, a WordPress plugin, from version n/a through 4.5.2. This issue allows for Stored XSS, potentially enabling attackers to inject malicious scripts into web pages viewed by other users. The vulnerability arises from improper neutralization of input during web page generation. Defenders should assess exposure, prioritize verification and reme [truncated]

MEDIUM Brainstorm Force CVE published 2026-10-05

CVE-2026-102393

A Cross-site Scripting vulnerability exists in Brainstorm Force Starter Templates, affecting versions from n/a through 4.7.7. This issue allows for Stored XSS. The vulnerability enables attackers to inject malicious JavaScript code into websites, potentially leading to unauthorized actions or data theft. Defenders should assess exposure and prioritize updates to prevent potential XSS attacks, especially i [truncated]

MEDIUM Brainstorm Force CVE published 2026-09-11

CVE-2026-62134

CVE-2026-62134 Contributor Insecure Direct Object References (IDOR) in Starter Templates <= 4.7.5 versions. This medium-severity vulnerability requires verification of exposure and patch application to prevent potential exploitation. Defenders responsible for Starter Templates installations should assess exposure and apply patches. The CVE record and NVD entry provide limited information about the vulnera [truncated]

MEDIUM Brainstorm Force CVE published 2026-08-06

CVE-2026-66688

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:17:22.107Z and has not been modified since then. This CVE-2026-66688 record details a Contributor Cross Site Scripting (XSS) vulnerability in Ultimate Addons for Elementor version 1.45.2 or earlier, classified as CWE-79. The vulnerability allows an attacker to inject malicious scripts into web [truncated]

CRITICAL Brainstorm Force CVE published 2026-07-13

CVE-2026-57401

CVE-2026-57401 is a Path Traversal vulnerability in the SureDash plugin, affecting versions from n/a through <= 1.8.0. The vulnerability has a CVSS score of 9.9 and is considered CRITICAL. Users of the SureDash plugin, especially those using versions up to 1.8.0, should be aware of this vulnerability and take necessary actions to mitigate the risk. The vulnerability allows attackers to traverse the direct [truncated]

HIGH Brainstorm Force CVE published 2026-06-17

CVE-2026-54813

A high-severity SQL injection vulnerability, known as CVE-2026-54813, has been discovered in the SureDash plugin. This vulnerability, with a CVSS score of 8.5, allows for blind SQL injection attacks. The issue affects SureDash versions from n/a through 1.8.0. Organizations using this plugin are advised to take immediate action to mitigate the risk. The vulnerability was published on June 17, 2026, and has [truncated]

CRITICAL Brainstorm Force CVE published 2026-06-15

CVE-2026-49781

CVE-2026-49781 is a critical vulnerability in the OttoKit plugin, specifically affecting versions up to and including 1.1.27. This vulnerability allows for unauthenticated PHP object injection, which can lead to severe consequences, including code execution, data breaches, and system compromise. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 9.8, indicating a critical sever [truncated]

HIGH Brainstorm Force CVE published 2026-06-15

CVE-2026-39470

CVE-2026-39470 is a HIGH severity vulnerability in WooCommerce Cart Abandonment Recovery plugin versions < 2.1.0. The vulnerability allows for Privilege Escalation by a Shop manager. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 7.2.

MEDIUM Brainstorm Force CVE published 2026-05-19

CVE-2026-45442

A Missing Authorization vulnerability in the Presto Player WordPress plugin (versions through 4.1.3) allows authenticated attackers with low privileges to exploit incorrectly configured access control security levels. The vulnerability, classified as CWE-862, was disclosed on May 19, 2026 and carries a CVSS 3.1 score of 4.3 (Medium severity). The issue stems from broken access control mechanisms that fail [truncated]

HIGH Brainstorm Force CVE published 2026-04-08

CVE-2026-39479

A SQL Injection vulnerability was found in Brainstorm Force OttoKit suretriggers. This issue allows for Blind SQL Injection and has a CVSS score of 7.6. The vulnerability affects OttoKit from n/a through <= 1.1.20. This type of vulnerability can allow attackers to manipulate database queries, potentially leading to unauthorized access or data breaches. Users of Brainstorm Force OttoKit suretriggers should [truncated]

MEDIUM Brainstorm Force CVE published 2026-04-08

CVE-2026-39477

A Missing Authorization vulnerability was discovered in the CartFlows cartflows plugin, affecting versions from n/a through 2.2.3. This issue allows attackers to exploit incorrectly configured access control security levels. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. Users of CartFlows cartflows plugin, especially those with versions prior to an updated version beyond 2.2.3, shoul [truncated]