PatchSiren

Roxnor CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Roxnor CVE published 2026-07-27

CVE-2026-59560

PatchSiren debrief for CVE-2026-59560, a Subscriber Broken Access Control vulnerability in FundEngine versions <= 1.7.8. This vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. The CVE record was published on 2026-07-27T15:17:06.303Z and last modified on 2026-07-27T17:46:02.447Z. Users of FundEngine plugin versions <= 1.7.8 should apply patches or mitigations to prevent potential unauthorized access.

MEDIUM Roxnor CVE published 2026-07-13

CVE-2026-57406

A Missing Authorization vulnerability in Roxnor FundEngine wp-fundraising-donation allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FundEngine: from n/a through <= 1.7.6. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM severity. Users of FundEngine wp-fundraising-donation plugin for WordPress should verify their installation and update to a [truncated]

MEDIUM Roxnor CVE published 2026-04-08

CVE-2026-39644

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T09:16:35.213Z and has not been modified since then. The NVD entry is currently Deferred. This CVE-2026-39644 vulnerability, classified as a Missing Authorization issue in the Wp Ultimate Review plugin, allows attackers to exploit incorrectly configured access control security levels. The vulnerab [truncated]

MEDIUM roxnor CVE published 2026-04-04

CVE-2026-2600

The ElementsKit Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ekit_tab_title' parameter in the Simple Tab widget in all versions up to, and including, 3.7.9. This vulnerability allows authenticated attackers with contributor-level access and above to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page [truncated]