PatchSiren

ShapedPlugin LLC CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM ShapedPlugin LLC CVE published 2026-07-27

CVE-2026-66433

A Cross Site Scripting (XSS) vulnerability was found in the Location Weather plugin up to version 3.0.6. This issue allows contributors to inject malicious scripts, potentially leading to unauthorized modifications or data exposure. The vulnerability has a CVSS score of 6.5, indicating a medium severity level. Users of the Location Weather plugin should be aware of this vulnerability and take necessary pr [truncated]

HIGH ShapedPlugin LLC CVE published 2026-07-13

CVE-2026-59521

A Deserialization of Untrusted Data vulnerability was discovered in ShapedPlugin LLC Real Testimonials testimonial-free, potentially allowing Object Injection. The issue affects Real Testimonials versions from n/a through <= 3.1.15. The CVSS score for this vulnerability is 7.2, indicating a HIGH severity. This vulnerability could allow attackers to inject objects, potentially leading to security breaches. [truncated]

CRITICAL ShapedPlugin, LLC CVE published 2026-06-05

CVE-2026-49777

CVE-2026-49777 is a critical vulnerability in the Product Slider Pro for WooCommerce plugin, caused by improper validation of specified quantity in input. This vulnerability, with a CVSS score of 10, allows for malicious software to be implanted. The affected versions of the plugin are from n/a to 3.5.4.