PatchSiren

gm_alex CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM gm_alex CVE published 2026-08-05

CVE-2026-15281

The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the wp_ajax_save-attachment-compat AJAX action in versions up to, and including, 2.3.12. This vulnerability allows authenticated attackers with subscriber-level access and above to append additional SQL queries into existing queries, potentially leading to sensitive information disclosure. Th [truncated]