PatchSiren

pixelyoursite CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH pixelyoursite CVE published 2026-05-20

CVE-2026-7613

CVE-2026-7613 is a stored cross-site scripting issue in the Cost of Goods by PixelYourSite WordPress plugin, affecting versions up to and including 1.2.12. Because the flaw is reachable through the csvdata[0][cost_of_goods_value] parameter and can be triggered by unauthenticated input, site owners should treat it as a high-priority web application risk.

HIGH PixelYourSite CVE published 2026-05-20

CVE-2026-9010

The Boost plugin for WordPress is vulnerable to time-based SQL Injection via the 'current_url' and 'user_name' parameters in versions up to, and including, 2.0.3. This vulnerability allows unauthenticated attackers to append additional SQL queries into existing queries, potentially leading to sensitive information disclosure. The vulnerability is due to insufficient escaping on user-supplied parameters an [truncated]

CRITICAL PixelYourSite CVE published 2026-05-20

CVE-2026-7637

The Boost plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.0.3 via deserialization of untrusted input in the STYXKEY-BOOST_USER_LOCATION cookie. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is present in the vulnerable software, which means this vulnerability has no impact unless another plugin or theme contai [truncated]