PatchSiren

loopus CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH loopus CVE published 2026-01-08

CVE-2025-22725

A Cross-site Scripting (XSS) vulnerability exists in the WP Virtual Assistant plugin, affecting versions from n/a through 3.1. This issue allows for Stored XSS, potentially enabling attackers to inject malicious scripts into web pages. The vulnerability has a CVSS score of 7.1 and is considered HIGH severity. Defenders and administrators of WordPress installations using the WP Virtual Assistant plugin sho [truncated]

HIGH loopus CVE published 2026-01-08

CVE-2025-22715

A Missing Authorization vulnerability in the WP Attractive Donations System - Easy Stripe & Paypal donations plugin allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Attractive Donations System - Easy Stripe & Paypal donations versions from n/a through 1.25. The vulnerability could lead to potential unauthorized actions on the plugin, emphasizing the need for v [truncated]