PatchSiren

Cozmoslabs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Cozmoslabs CVE published 2026-07-27

CVE-2026-59539

A HIGH severity vulnerability was found in Paid Member Subscriptions plugin version 3.0.7 and earlier. The vulnerability is an Insecure Direct Object References (IDOR) issue, which could allow attackers to access sensitive data. This issue affects users of Paid Member Subscriptions plugin version 3.0.7 and earlier. The vulnerability allows unauthenticated attackers to access sensitive data by manipulating [truncated]

LOW Cozmoslabs CVE published 2026-07-13

CVE-2026-61971

A vulnerability was found in Cozmoslabs User Profile Picture metronet-profile-picture. It has been classified as problematic. Affected is an unknown function of the component User-Controlled Key Handler. The manipulation leads to authorization bypass. The issue affects User Profile Picture: from n/a through <= 2.6.3. This vulnerability allows attackers to bypass authorization due to incorrectly configured [truncated]

HIGH Cozmoslabs CVE published 2026-06-17

CVE-2026-42385

CVE-2026-42385 is a high-severity Unauthenticated Cross Site Scripting (XSS) vulnerability in Profile Builder Pro versions <= 3.15.0. The vulnerability has a CVSS score of 7.1 and is considered HIGH. It was published on 2026-06-17T13:20:40.067Z and last modified on 2026-06-17T15:16:50.517Z. Users of Profile Builder Pro should update to a patched version to prevent exploitation. The vulnerability allows at [truncated]

HIGH Cozmoslabs CVE published 2026-06-15

CVE-2026-39514

CVE-2026-39514 is a HIGH severity Unauthenticated Cross Site Scripting (XSS) vulnerability affecting Paid Member Subscriptions plugin versions <= 2.17.3. The vulnerability has a CVSS score of 7.1 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-39514). The vulnerability was reported by Patchstack.