PatchSiren

massiveshift CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM massiveshift CVE published 2026-04-08

CVE-2026-39699

The AI Workflow Automation Lite plugin for WordPress has a missing authorization vulnerability, which could allow attackers to exploit incorrectly configured access control security levels. This issue affects AI Workflow Automation from n/a through <= 1.4.2, with a CVSS score of 5.3 and a severity of MEDIUM. Users should verify their installations and ensure they are up-to-date to prevent potential exploi [truncated]