PatchSiren

ThemeGrill CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL ThemeGrill CVE published 2026-06-17

CVE-2026-54807

CVE-2026-54807 is a critical vulnerability in the Registration Form for WooCommerce plugin, with a CVSS score of 9.8. It allows for unauthenticated privilege escalation and affects versions <= 1.0.9. The vulnerability was published on 2026-06-17 and last modified on 2026-06-17. Users of this plugin should take immediate action to mitigate this vulnerability.

HIGH ThemeGrill CVE published 2026-06-17

CVE-2026-49081

CVE-2026-49081 is a HIGH severity vulnerability (CVSS Score: 8.2) affecting the User Registration Stripe plugin versions <= 1.3.12. This vulnerability involves unauthenticated broken access control. The CVE was published on 2026-06-17T13:20:46.200Z and last modified on 2026-06-17T15:16:59.627Z. Users of the affected plugin should take immediate action to mitigate potential risks. This vulnerability allows [truncated]

HIGH ThemeGrill CVE published 2026-06-17

CVE-2026-40726

CVE-2026-40726 is a HIGH severity vulnerability (CVSS Score: 8.2) in the User Registration Stripe plugin versions <= 1.3.14. This vulnerability involves unauthenticated broken access control, potentially allowing attackers to access sensitive user registration information. The vulnerability was published on June 17, 2026, and last modified on the same day. Organizations using this plugin should take immed [truncated]

MEDIUM ThemeGrill CVE published 2026-06-15

CVE-2026-42743

CVE-2026-42743 is a MEDIUM severity vulnerability (CVSS Score: 6.5) affecting Masteriyo - LMS plugin versions up to 2.1.8. The vulnerability is caused by unauthenticated broken authentication. The CVE was published on 2026-06-15T21:16:57.117Z and last modified on 2026-06-15T21:24:32.790Z.

HIGH ThemeGrill CVE published 2026-06-15

CVE-2026-39524

CVE-2026-39524 is a HIGH severity vulnerability (CVSS Score: 7.5) in the Masteriyo - LMS plugin up to version 2.1.5. The vulnerability is caused by unauthenticated broken access control, which could allow attackers to bypass payment controls. The vulnerability was published on [cvePublishedAt] and last modified on [cveModifiedAt].

HIGH ThemeGrill CVE published 2026-06-15

CVE-2026-25425

CVE-2026-25425 is a high severity vulnerability (CVSS Score: 7.5) affecting User Registration plugin versions <= 5.1.2. This vulnerability is categorized as Unauthenticated Broken Access Control. According to the [NVD detail resourceLinkAnnotations:nvd], the vulnerability has a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H. The [CVE record resourceLinkAnnotations:cve-org] was published on 20 [truncated]

HIGH ThemeGrill CVE published 2026-06-15

CVE-2026-49111

A HIGH severity vulnerability (CVSS 8.8) was found in Masteriyo - LMS, allowing for Privilege Escalation. This issue affects Masteriyo - LMS: from n/a through 2.2.0.