PatchSiren

Justin Kruit CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Justin Kruit CVE published 2026-08-06

CVE-2026-66678

The Advanced Custom Fields: Font Awesome Field plugin, versions <= 6.1.1, contains a Broken Access Control vulnerability. This vulnerability, classified as MEDIUM severity with a CVSS score of 4.3, could allow unauthorized access to sensitive information or functionality. Users of this plugin should be aware of the potential risks and take necessary actions to mitigate them. The CVE record was published o [truncated]

MEDIUM Justin Kruit CVE published 2026-05-27

CVE-2026-49044

A stored cross-site scripting (XSS) vulnerability exists in the Advanced Custom Fields: Font Awesome Field WordPress plugin, affecting versions up to and including 5.0.2. The vulnerability stems from improper neutralization of input during web page generation (CWE-79). An attacker with low privileges can inject malicious scripts that execute in the context of other users' browsers, potentially leading to [truncated]