PatchSiren

Brainstorm Force CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Brainstorm Force CVE published 2026-08-06

CVE-2026-66688

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:17:22.107Z and has not been modified since then. This CVE-2026-66688 record details a Contributor Cross Site Scripting (XSS) vulnerability in Ultimate Addons for Elementor version 1.45.2 or earlier, classified as CWE-79. The vulnerability allows an attacker to inject malicious scripts into web [truncated]

CRITICAL Brainstorm Force CVE published 2026-07-13

CVE-2026-57401

CVE-2026-57401 is a Path Traversal vulnerability in the SureDash plugin, affecting versions from n/a through <= 1.8.0. The vulnerability has a CVSS score of 9.9 and is considered CRITICAL. Users of the SureDash plugin, especially those using versions up to 1.8.0, should be aware of this vulnerability and take necessary actions to mitigate the risk. The vulnerability allows attackers to traverse the direct [truncated]

HIGH Brainstorm Force CVE published 2026-06-17

CVE-2026-54813

A high-severity SQL injection vulnerability, known as CVE-2026-54813, has been discovered in the SureDash plugin. This vulnerability, with a CVSS score of 8.5, allows for blind SQL injection attacks. The issue affects SureDash versions from n/a through 1.8.0. Organizations using this plugin are advised to take immediate action to mitigate the risk. The vulnerability was published on June 17, 2026, and has [truncated]

CRITICAL Brainstorm Force CVE published 2026-06-15

CVE-2026-49781

CVE-2026-49781 is a critical vulnerability in the OttoKit plugin, specifically affecting versions up to and including 1.1.27. This vulnerability allows for unauthenticated PHP object injection, which can lead to severe consequences, including code execution, data breaches, and system compromise. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 9.8, indicating a critical sever [truncated]

HIGH Brainstorm Force CVE published 2026-06-15

CVE-2026-39470

CVE-2026-39470 is a HIGH severity vulnerability in WooCommerce Cart Abandonment Recovery plugin versions < 2.1.0. The vulnerability allows for Privilege Escalation by a Shop manager. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 7.2.

MEDIUM Brainstorm Force CVE published 2026-05-19

CVE-2026-45442

A Missing Authorization vulnerability in the Presto Player WordPress plugin (versions through 4.1.3) allows authenticated attackers with low privileges to exploit incorrectly configured access control security levels. The vulnerability, classified as CWE-862, was disclosed on May 19, 2026 and carries a CVSS 3.1 score of 4.3 (Medium severity). The issue stems from broken access control mechanisms that fail [truncated]

HIGH Brainstorm Force CVE published 2026-04-08

CVE-2026-39479

A SQL Injection vulnerability was found in Brainstorm Force OttoKit suretriggers. This issue allows for Blind SQL Injection and has a CVSS score of 7.6. The vulnerability affects OttoKit from n/a through <= 1.1.20. This type of vulnerability can allow attackers to manipulate database queries, potentially leading to unauthorized access or data breaches. Users of Brainstorm Force OttoKit suretriggers should [truncated]

MEDIUM Brainstorm Force CVE published 2026-04-08

CVE-2026-39477

A Missing Authorization vulnerability was discovered in the CartFlows cartflows plugin, affecting versions from n/a through 2.2.3. This issue allows attackers to exploit incorrectly configured access control security levels. The vulnerability has a CVSS score of 4.3 and a severity of MEDIUM. Users of CartFlows cartflows plugin, especially those with versions prior to an updated version beyond 2.2.3, shoul [truncated]