These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.2. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attacker [truncated]
The All in One SEO – AI SEO Plugin to Boost SEO Rankings & Traffic (Schema, Local SEO, Sitemap & SEO Insights) plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via URL Pathname in all versions up to, and including, 5.0.1.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will e [truncated]
The WPForms plugin for WordPress, specifically versions up to and including 2.0.2, is vulnerable to Reflected Cross-Site Scripting via the 'page_title' POST parameter. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts into pages that execute if they can successfully trick a user into performing an action such as clicking on a link. The vulnerability is due to insufficient [truncated]
The Custom Twitter Feeds – A Tweets Widget or X Feed Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'buttoncolor' Shortcode Attribute in all versions up to, and including, 2.8.0. This is due to insufficient input sanitization and output escaping, allowing authenticated attackers with contributor-level access and above to inject arbitrary web scripts. These scripts will ex [truncated]
The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vulnerable to Insecure Direct Object Reference / Authorization Bypass leading to Arbitrary Attachment Deletion. This issue affects versions up to, and including, 1.8.11.1 and is exploitable via the profile avatar update flow. An authenticated attacker with Subscriber-level access and above [truncated]
The PDF Embedder plugin for WordPress exposes sensitive configuration data through the `enqueue_block_assets` hook in versions up to and including 4.9.3. Authenticated users with contributor-level access or higher can extract this data. When the premium add-on is installed and a license key has been saved, the exposed data includes the license key. On Lite-only installations, the exposure is limited to no [truncated]
A Cross-Site Request Forgery (CSRF) vulnerability in the Easy Digital Downloads WordPress plugin allows unauthenticated attackers to overwrite Square payment gateway credentials by tricking a logged-in administrator into visiting a malicious link. The flaw exists in the `handle_oauth_redirect()` function, which processes OAuth tokens from user-supplied GET parameters without nonce verification. This could [truncated]
CVE-2026-8832 is a high-severity remote code execution vulnerability in the WPCode WordPress plugin (versions up to and including 2.3.5), published 2026-05-27. The root cause is a missing capability_type parameter when registering the 'wpcode' custom post type, causing WordPress to fall back to standard post capabilities. This allows author-level users to create and publish executable PHP snippets via XML [truncated]
The Slider by Soliloquy – Responsive Image Slider for WordPress plugin is vulnerable to Sensitive Information Exposure. Authenticated attackers with subscriber-level access can extract draft slider metadata, including unpublished media URLs, captions, and slider configuration authored by administrators or editors. This vulnerability has a CVSS score of 4.3 and is considered Medium severity. Administrators [truncated]
The NextGEN Gallery WordPress plugin (versions ≤4.2.0) contains an Insecure Direct Object Reference (IDOR) vulnerability in its REST API image deletion endpoint. The DELETE /imagely/v1/images/{id} endpoint only validates the 'NextGEN Manage gallery' capability without verifying gallery ownership or checking for the 'NextGEN Manage others gallery' permission. This authorization gap allows authenticated att [truncated]
The All in One SEO plugin for WordPress, versions up to and including 4.9.7, exposes sensitive internal option data through localized script variables in post editor contexts. The vulnerability stems from passing unmasked API/OAuth tokens and license-related values via `wp_localize_script()` to the browser, where contributor-level users and above can view them in page source. This represents an informatio [truncated]
The ExactMetrics – Google Analytics Dashboard for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 9.1.2. This is due to missing capability checks in the get_ads_access_token() and reset_experience() AJAX handlers. While the mi-admin-nonce is localized on all admin pages (including profile.php which subscribers can access), and while other similar AJAX [truncated]