PatchSiren

codepeople CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM codepeople CVE published 2026-06-27

CVE-2026-13335

The CodePeople Post Map for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cpm_point' Post Meta in all versions up to, and including, 1.2.6. This vulnerability allows authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability has a CVSS score of [truncated]

MEDIUM codepeople CVE published 2026-06-18

CVE-2026-12111

The Appointment Booking Calendar plugin for WordPress has a Sensitive Information Exposure vulnerability (CVE-2026-12111, CVSS Score: 4.3) in versions up to and including 1.4.01. This vulnerability allows authenticated attackers with Contributor-level access or above to extract customer booking information from any calendar managed by the plugin. The issue arises from insufficient authorization and missin [truncated]

HIGH codepeople CVE published 2026-06-15

CVE-2026-48882

A high-severity vulnerability, CVE-2026-48882, was discovered in the WP Time Slots Booking Form plugin, affecting versions up to and including 1.2.50. This vulnerability allows subscribers to inject SQL, potentially leading to unauthorized data access or manipulation. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 8.5, indicating a high level of severity. The vulnerability [truncated]

HIGH codepeople CVE published 2026-06-15

CVE-2026-40791

CVE-2026-40791 is a HIGH severity Unauthenticated Cross Site Scripting (XSS) vulnerability in WP Time Slots Booking Form versions <= 1.2.46. The vulnerability has a CVSS score of 7.1 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-40791).