PatchSiren

lcweb-projects CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM lcweb-projects CVE published 2026-04-08

CVE-2026-4025

The PrivateContent Free plugin for WordPress has a Stored Cross-Site Scripting vulnerability via the 'align' shortcode attribute in the [pc-login-form] shortcode. This issue affects all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping. The vulnerability allows authenticated attackers with Contributor-level access and above to inject arbitrary web scripts. Use [truncated]