PatchSiren

Nexcess CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Nexcess CVE published 2026-08-06

CVE-2026-66696

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:17:22.730Z and has not been modified since then. The vulnerability is a Contributor Sensitive Data Exposure in Gutenberg Blocks by Kadence Blocks <= 3.7.8 versions. Defenders and administrators using Kadence Blocks versions <= 3.7.8 should be aware of the potential sensitive data exposure vuln [truncated]

HIGH Nexcess CVE published 2026-08-06

CVE-2026-66690

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:17:22.230Z and has not been modified since then. CVE-2026-66690 is an unauthenticated Cross Site Scripting (XSS) vulnerability in GiveWP plugin versions <= 4.16.5. The vulnerability has a CVSS score of 7.1 and requires no user interaction (UI:R) to exploit. The attack vector is network (AV:N) [truncated]

CRITICAL Nexcess CVE published 2026-08-06

CVE-2026-28005

CVE-2026-28005 is a critical unauthenticated privilege escalation vulnerability in Kadence WooCommerce Email Designer plugin versions <= 1.5.19. This vulnerability allows attackers to potentially gain elevated privileges, impacting administrators and users of the plugin. The CVE record was published on 2026-08-06T15:16:51.560Z and has not been modified since then. Defenders should verify affected product [truncated]

MEDIUM Nexcess CVE published 2026-07-27

CVE-2026-65567

CVE-2026-65567 is a MEDIUM severity vulnerability with a CVSS score of 5.3, classified as Unauthenticated Broken Access Control in Event Tickets plugin versions <= 5.29.0.1. The vulnerability allows for potential unauthorized access. Users of Event Tickets plugin versions <= 5.29.0.1 should verify their installations and update to a patched version if available. This vulnerability has not been modified si [truncated]

HIGH Nexcess CVE published 2026-07-13

CVE-2026-57705

The CVE-2026-57705 record, published on 2026-07-13T10:16:37.493Z, discloses a Missing Authorization vulnerability in the Event Tickets plugin for WordPress. This vulnerability allows attackers to exploit incorrectly configured access control security levels. The issue affects Event Tickets from n/a through <= 5.28.5. Users should verify and apply patches to prevent potential authorization bypass attacks. [truncated]