PatchSiren

saadiqbal CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH saadiqbal CVE published 2026-08-05

CVE-2026-6627

The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to unauthorized modification and deletion of Stripe payment credentials in all versions up to, and including, 1.1.1. This is due to missing capability checks and nonce verification on the `wpf_stripe_callback_success()` and `wpf_stripe_disconnect()` functions, both hooked to `admin_init`. The `admin_init` hook fires [truncated]

MEDIUM saadiqbal CVE published 2026-08-01

CVE-2026-11995

The Gutena Forms plugin for WordPress has an authorization bypass vulnerability in all versions up to and including 1.9.0. This allows unauthenticated attackers to modify form submission entries, potentially leading to data tampering. The plugin's vulnerability is attributed to the nonce issued by check_ajax_referer() not functioning as an authorization barrier. Affected product deployments should be conf [truncated]

MEDIUM saadiqbal CVE published 2026-07-11

CVE-2026-12738

The WP Easy Pay – Payment and Donation form Builder for Square plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.5.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to set the status of arbitrary posts and pages to 'd [truncated]

MEDIUM saadiqbal CVE published 2026-07-08

CVE-2026-12097

The User Management plugin for WordPress has an authorization bypass vulnerability in all versions up to and including 1.2. This allows unauthenticated attackers to modify the plugin's export field configuration, potentially leading to data exposure and integrity risks. Administrators of WordPress installations using the User Management plugin should assess and mitigate this vulnerability. The vulnerabili [truncated]

MEDIUM saadiqbal CVE published 2026-06-17

CVE-2026-8607

The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wrap' Shortcode Attribute in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitra [truncated]