PatchSiren

geotargetingwp CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review geotargetingwp CVE published 2026-08-30

CVE-2026-14307

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-30T07:17:20.000Z and has not been modified since then. The geotargetingwp WordPress plugin before version 3.5.6.2 does not sanitise or escape several parameters before reflecting them back in AJAX responses served with an HTML content type, potentially allowing unauthenticated attackers to inject ar [truncated]