PatchSiren

MWP Development CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM MWP Development CVE published 2026-04-08

CVE-2026-39680

A Missing Authorization vulnerability in the Diet Calorie Calculator plugin for WordPress, affecting versions from n/a through 1.1.1, allows attackers to exploit incorrectly configured access control security levels. This issue has a CVSS score of 5.3 and is classified as MEDIUM severity. The vulnerability enables attackers to bypass authorization mechanisms due to incorrectly configured access control se [truncated]