PatchSiren

dFactory CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH dFactory CVE published 2026-06-26

CVE-2026-56041

CVE-2026-56041 is a high-severity Unauthenticated Cross Site Scripting (XSS) vulnerability in the Responsive Lightbox plugin for WordPress, affecting versions up to 2.7.6. The vulnerability has a CVSS score of 7.1 and was published on June 26, 2026. The CVE record and NVD details provide information on this vulnerability. Patchstack has provided a mitigation reference for this issue. Users of the Responsi [truncated]

MEDIUM dFactory CVE published 2026-04-08

CVE-2026-39616

A vulnerability was found in the Download Attachments plugin for WordPress, affecting versions from n/a through 1.4.0. This issue allows for an Authorization Bypass Through User-Controlled Key vulnerability, which could potentially enable unauthorized access to sensitive information. The vulnerability has a CVSS score of 5.3 and a severity rating of MEDIUM. The Common Vulnerability Scoring System (CVSS) v [truncated]