PatchSiren

dreamstechnologies CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL dreamstechnologies CVE published 2026-05-05

CVE-2025-13618

The Mentoring plugin for WordPress has a critical vulnerability allowing unauthenticated attackers to register with administrator-level user accounts due to improper role restrictions in the mentoring_process_registration() function. This issue affects all versions up to and including 1.2.8. The vulnerability's impact requires verification from official sources due to limited information on exploitation o [truncated]