PatchSiren

cyberlord92 CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH cyberlord92 CVE published 2026-08-05

CVE-2026-12000

The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 1.4.0. This is due to the plugin's REST guards sourcing their restricted-ID list exclusively from a function that only reads per-page metabox options, never consulting global toggles that the plugin's UI describes as making all Pages and Posts private. This allows unauthentica [truncated]

CRITICAL cyberlord92 CVE published 2026-07-16

CVE-2026-15013

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion. The plugin incorrectly handles the `SignatureMethod` Algorithm attribute from the `SAMLResponse` parameter, allowing attackers to forge a SAML assertion and gain administrator-level account takeover. This critical vulnerability affects administrators and users of WordPres [truncated]

CRITICAL cyberlord92 CVE published 2026-07-10

CVE-2026-12761

The miniOrange Social Login and Register plugin for WordPress is vulnerable to authentication bypass leading to account takeover in versions up to and including 7.7.0. This is due to the Profile Completion flow accepting an arbitrary email address via the 'email_field' POST parameter without verifying that the email belongs to the identity returned by the OAuth provider, combined with send_otp_token() ret [truncated]