PatchSiren

JoomUnited CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM JoomUnited CVE published 2026-09-05

CVE-2026-14975

The WP File Download plugin for WordPress is vulnerable to Directory Traversal, allowing authenticated attackers with subscriber-level access to read arbitrary files, potentially exposing sensitive information. This vulnerability exists in all versions up to, and including, 6.3.8 via the 'remoteurl' parameter. An attacker can poison the _wpfd_file_metadata['file'] post-meta value and then access the trave [truncated]

HIGH JoomUnited CVE published 2026-09-02

CVE-2026-14982

The WP File Download plugin for WordPress has a vulnerability allowing authenticated attackers with subscriber-level access to delete arbitrary files, potentially leading to remote code execution. This vulnerability exists due to insufficient file path validation in the delete function across all versions of the plugin. An attacker can exploit this by making two requests: one to persist a path-traversal s [truncated]

HIGH joomunited CVE published 2026-06-24

CVE-2026-9643

The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI server variable in all versions up to, and including, 4.5.18. The plugin's `wpmsTemplateRedirect()` hook detects a 404 and concatenates `$_SERVER['HTTP_HOST']` with the raw `$_SERVER['REQUEST_URI']`, inserting the value into the `wp_wpms_links.link_url` column via `$wpdb->insert()`. This a [truncated]

MEDIUM joomunited CVE published 2026-06-24

CVE-2026-11370

The WP Meta SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.5.18 via the 'new_link' parameter. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services. The H [truncated]

HIGH Joomunited CVE published 2026-06-17

CVE-2026-9690

CVE-2026-9690 is a high-severity vulnerability in WP Media folder Addon versions <= 4.0.1. It allows unauthenticated arbitrary file downloads, posing a significant risk to affected systems. The vulnerability has a CVSS score of 7.5 and is considered HIGH severity. The CVE was published on 2026-06-17T13:21:35.147Z and last modified on 2026-06-17T17:17:28.293Z. Users of the affected plugin should take immed [truncated]