AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:17:15.483Z and has not been modified since then. CVE-2026-65517 is an unauthenticated Cross Site Scripting (XSS) vulnerability in Easy PayPal Buy Now Button <= 2.0.4 versions. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity. Affected systems may be exposed to poten [truncated]
CVE-2026-41471 is a HIGH severity (CVSS 8.2) information disclosure vulnerability in the Easy PayPal Events & Tickets WordPress plugin, affecting versions prior to 1.4. The vulnerability resides in the `scan_qr.php` endpoint, which fails to implement authentication or authorization checks when processing QR code scan requests. Unauthenticated attackers can exploit sequential WordPress post ID enumeration [truncated]