PatchSiren

ivijanstefan CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH ivijanstefan CVE published 2026-10-03

CVE-2026-96575

The Transliterator – Multilingual and Multi-script Text Conversion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Content due to insufficient input sanitization and output escaping. This allows unauthenticated attackers to inject web scripts that execute when a user accesses an injected page. The vulnerability exists in all versions up to, and including, 2.5.8 of the Transli [truncated]