AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-27T15:17:05.483Z and has not been modified since then. CVE-2026-59553 is an Unauthenticated Cross Site Scripting (XSS) vulnerability in Product Feed Manager plugin versions up to 7.6.1. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity. Users of Product Feed Manager plugin [truncated]
The Product Feed Manager For WooCommerce – Sell on 200+ Online Marketplaces plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 's' Search Parameter in all versions up to, and including, 7.6.1 due to insufficient input sanitization and output escaping. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tri [truncated]
CVE-2026-57417 is a Stored XSS vulnerability in Cart Lift plugin, affecting versions up to 3.1.57. The issue allows attackers to inject malicious scripts, potentially leading to unauthorized actions and data breaches. This vulnerability has been publicly disclosed and has a CVSS score of 7.1, indicating a high severity. Users of the Cart Lift plugin, especially those with untrusted user input, should prio [truncated]