PatchSiren

cornelraiu-1 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH cornelraiu-1 CVE published 2026-08-05

CVE-2026-7444

The Search Analytics for WP plugin for WordPress has a Cross-Site Request Forgery vulnerability in all versions up to and including 1.4.16. This is due to missing or incorrect nonce validation on the `process_bulk_action()` function of `MWTSA_Stats_Table`. The vulnerability allows unauthenticated attackers to delete arbitrary search-term records, including all associated search-history rows, via a forged [truncated]