PatchSiren

Marcin CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Marcin CVE published 2026-09-10

CVE-2026-81784

A Deserialization of Untrusted Data vulnerability in the Wise Chat plugin for WordPress, specifically affecting versions from n/a through 3.4.2, has been identified. This issue allows for Object Injection, posing a significant risk to affected systems. The vulnerability has a CVSS score of 8.1 and is classified as HIGH severity. Defenders should assess exposure and prioritize remediation to prevent potent [truncated]

MEDIUM Marcin CVE published 2026-08-18

CVE-2026-66636

A Cross-site Scripting (XSS) vulnerability exists in the Wise Chat plugin for WordPress, affecting versions from n/a through 3.4.2. This issue allows for Stored XSS, potentially enabling attackers to inject malicious scripts into web pages. Defenders should assess exposure and prioritize updates to mitigate potential XSS attacks. The vulnerability has a CVSS score of 6.5 with MEDIUM severity. To address t [truncated]