PatchSiren

fsylum CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL fsylum CVE published 2026-01-06

CVE-2025-15001

The FS Registration Password plugin for WordPress has a critical vulnerability allowing unauthenticated attackers to change arbitrary user passwords, including administrators, due to improper identity validation. This vulnerability, tracked as CVE-2025-15001, has a CVSS score of 9.8, indicating a high severity level. The plugin's failure to validate user identity prior to updating passwords enables attack [truncated]