PatchSiren

Dasinfomedia CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Dasinfomedia CVE published 2026-01-07

CVE-2025-31642

A Cross-site Scripting (XSS) vulnerability exists in the WPCHURCH plugin for WordPress, affecting versions from n/a through 2.7.0. This issue allows for Reflected XSS attacks. The vulnerability arises from improper neutralization of input during web page generation, potentially leading to malicious script execution. Defenders responsible for WordPress deployments using the WPCHURCH plugin, particularly th [truncated]