PatchSiren

Themehigh CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Themehigh CVE published 2026-07-25

CVE-2026-14955

The Checkout Field Editor for WooCommerce (Pro) plugin for WordPress is vulnerable to Directory Traversal, allowing authenticated attackers with subscriber-level access to read arbitrary files. This vulnerability, tracked as CVE-2026-14955, has a CVSS score of 6.5 and is considered a medium priority due to its potential for sensitive information disclosure. The vulnerability exists in all versions up to, [truncated]

MEDIUM ThemeHigh CVE published 2026-05-25

CVE-2026-45217

CVE-2026-45217 is a medium-severity authentication bypass vulnerability in the Stripe Payment Gateway for WooCommerce WordPress plugin, affecting versions up to and including 5.0.7. The vulnerability, classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), enables password recovery exploitation, allowing attackers to potentially bypass authentication controls. The issue was publi [truncated]