PatchSiren

danieliser CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH danieliser CVE published 2026-09-18

CVE-2026-87915

The Popup Maker plugin for WordPress has a Stored Cross-Site Scripting vulnerability via the values[Name] parameter in all versions up to 1.24.0. This allows unauthenticated attackers to inject web scripts that execute when a user accesses an injected page. The vulnerability is caused by insufficient input sanitization and output escaping. The wp_kses sanitization applied on output is insufficient in this [truncated]

MEDIUM danieliser CVE published 2026-09-18

CVE-2026-15797

The Popup Maker plugin for WordPress has a Stored Cross-Site Scripting vulnerability via post_title in versions up to 1.24.0. Authenticated attackers with contributor-level access can inject web scripts that execute when a user accesses an injected page. This vulnerability allows attackers to create posts with malicious titles that, when viewed, execute arbitrary scripts. The issue arises from insufficien [truncated]