PatchSiren

dearhive CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM dearhive CVE published 2026-09-05

CVE-2026-8625

The Dear Flipbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (Custom HTML block inner HTML)' parameter in all versions up to, and including, 2.4.30 due to insufficient input sanitization and output escaping. This vulnerability allows authenticated attackers with contributor-level access to inject arbitrary web scripts, which can execute on pages accessed by use [truncated]

MEDIUM dearhive CVE published 2026-09-05

CVE-2026-8623

The Dear Flipbook plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (class attribute of .dvcss element)' parameter in all versions up to, and including, 2.4.30. Authenticated attackers with contributor-level access and above can inject arbitrary web scripts, which execute when a user accesses an injected page. This vulnerability allows for potential malicious script i [truncated]

MEDIUM DearHive CVE published 2026-05-27

CVE-2026-49047

A Missing Authorization vulnerability in the DearFlip WordPress plugin allows authenticated users with low privileges to exploit incorrectly configured access control security levels. The vulnerability affects all versions from n/a through 2.4.27. The issue was disclosed on 2026-05-27 and carries a CVSS 3.1 score of 4.3 (Medium severity), indicating limited impact on confidentiality with no impact on inte [truncated]