These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to blind SQL Injection via the `filter_data[comment_count]` parameter of the public `tableon_get_table_data` AJAX action in all versions up to, and including, 1.0.5.1. This vulnerability allows unauthenticated attackers to append additional SQL queries and extract sensitive information from the database. The vulnerability is [truncated]
CVE-2026-57409 is a Cross-site Scripting vulnerability in Active Products Tables for WooCommerce, a WordPress plugin. The vulnerability, known as DOM-Based XSS, arises from improper neutralization of input during web page generation. The CVE record was published on 2026-07-13T10:16:34.650Z and has not been modified since then. Users of Active Products Tables for WooCommerce plugin version 1.1.0 or earlier [truncated]
CVE-2026-39574 is a critical vulnerability in the InPost Gallery plugin for WordPress, affecting versions up to and including 2.1.4.6. This vulnerability allows unauthenticated attackers to inject malicious SQL code, potentially leading to data breaches or other security issues. The vulnerability has a CVSS score of 9.3, indicating a high severity level.
A medium-severity authorization bypass vulnerability in the FOX – Currency Switcher Professional for WooCommerce plugin allows authenticated attackers with Subscriber-level access or higher to impersonate privileged roles and obtain unauthorized pricing. The flaw exists in the `get_value()` function within `classes/fixed/fixed_user_role.php`, which trusts the attacker-controlled `$_REQUEST['wooc_order_use [truncated]
The BEAR – Bulk Editor and Products Manager Professional for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery. This issue, tracked as CVE-2026-1672, allows unauthenticated attackers to update WooCommerce product data, including prices and descriptions, due to missing nonce validation in the woobe_redraw_table_row() function. Site administrators and security teams should be awar [truncated]
A Missing Authorization vulnerability in RealMag777 FOX woocommerce-currency-switcher allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FOX: from n/a through <= 1.4.5. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Users of RealMag777 FOX woocommerce-currency-switcher plugin for WordPress should verify their installation and update [truncated]
A SQL Injection vulnerability was found in the FOX plugin for WooCommerce, allowing for Blind SQL Injection attacks. The issue affects FOX versions from n/a through 1.4.5. This vulnerability can be used to extract or modify sensitive data. Users of the FOX plugin for WooCommerce, particularly those with versions 1.4.5 or earlier, should be aware of this vulnerability and take steps to mitigate it. The CVE [truncated]
The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tableon_button' shortcode in all versions up to and including 1.0.4.4. This is due to insufficient input sanitization and output escaping on user-supplied shortcode attributes such as 'class', 'help_link', 'popup_title', and 'help_title'. Authenticated attackers with Contributor-level [truncated]