PatchSiren

Squadeno CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review Squadeno CVE published 2026-10-11

CVE-2026-107507

The Squadeno WordPress plugin before 1.12.0 does not enforce its restrictions on every way a sport can be saved, allowing users with the lowest-tier Trainer role to change the section, age group, author, password, comment settings, and date of a sport they are assigned to. This vulnerability allows unauthorized changes to sports data, potentially impacting data integrity and confidentiality. WordPress adm [truncated]