PatchSiren

Spiffy Plugin CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Spiffy Plugin CVE published 2026-08-28

CVE-2026-39071

The Spiffy Plugin for WordPress before version 5.0.9 is vulnerable to Stored Cross-Site Scripting via the Event Title field. This vulnerability allows an authenticated attacker with the lowest privileged role (contributor) to potentially inject scripts, redirect users, or control accounts. The CVE record was published on 2026-08-28T20:17:28.670Z. WordPress administrators and users of the Spiffy Plugin, es [truncated]