PatchSiren

spacetime CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Spacetime CVE published 2026-07-13

CVE-2026-57693

CVE-2026-57693 is a Cross-site Scripting vulnerability in Ad Inserter, a WordPress plugin. The vulnerability has a CVSS score of 6.5 and is classified as MEDIUM. The issue affects Ad Inserter from n/a through <= 2.8.11. The vulnerability is caused by Improper Neutralization of Input During Web Page Generation, also known as Cross-site Scripting. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/ [truncated]

MEDIUM spacetime CVE published 2026-07-03

CVE-2026-11900

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Insecure Direct Object Reference, allowing authenticated attackers with Contributor-level access and above to read the full content of arbitrary posts, including Private, Draft, Pending, Trashed, and password-protected posts owned by other users. This is due to insufficient authorization checks in the replace_ai_tags() functi [truncated]