These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-66437 is a Server Side Request Forgery (SSRF) vulnerability affecting Feedzy RSS Feeds versions up to 5.2.4. This issue allows contributors to make the server perform unintended requests, potentially bypassing access controls and interacting with internal or external services. The vulnerability has a CVSS score of 4.9, indicating a medium severity level. Users of Feedzy RSS Feeds plugin version 5 [truncated]
A MEDIUM severity vulnerability, CVE-2026-65563, was found in Orbit Fox by ThemeIsle. This vulnerability is an Author Cross Site Scripting (XSS) issue affecting versions up to 3.0.7. The vulnerability has a CVSS score of 5.9 and is classified as MEDIUM severity. It allows attackers to inject malicious scripts into the application, potentially leading to unauthorized actions or data breaches. Users of Orbi [truncated]
The CVE record for CVE-2026-65526 was published on 2026-07-23T12:18:45.393Z and has not been modified since then. The NVD entry is currently Deferred. This Blind SQL Injection vulnerability in the Visualizer plugin affects versions from n/a through 4.0.1, with a CVSS score of 8.5 and classified as HIGH severity. Security teams and administrators should verify plugin versions, review database configuration [truncated]
A Server-Side Request Forgery (SSRF) vulnerability was discovered in the Auto Featured Image (Auto Post Thumbnail) plugin for WordPress. This issue, tracked as CVE-2026-61970, allows attackers to perform Server Side Request Forgery. The vulnerability affects the plugin versions from n/a through <= 5.0.4. The vulnerability has a CVSS score of 4.9, indicating a medium severity level, with a CVSS vector of C [truncated]
The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.4.3 via the wpfs_update_failed_payment_status AJAX action. This makes it possible for unauthenticated attackers who can obtain a valid Stripe Payment Intent ID for the target site to manipulate payment records in the site's database. The handler is registered through both wp_ajax_ and wp [truncated]
The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More plugin for WordPress has a Stored Cross-Site Scripting vulnerability via admin settings in all versions up to, and including, 3.0.6. This vulnerability allows authenticated attackers with administrator-level permissions to inject arbitrary web scripts, which execute when a user accesses an injected page. The vulnera [truncated]
CVE-2026-42378 is a MEDIUM severity vulnerability (CVSS Score: 6.5) in the WP Full Stripe Free plugin for WordPress, affecting versions up to 8.4.1. The vulnerability is related to subscriber broken authentication. The CVE was published on 2026-06-15T21:16:53.863Z and modified on 2026-06-15T21:24:32.790Z.
CVE-2026-39507 is a HIGH severity Unauthenticated Cross Site Scripting (XSS) vulnerability in Social Slider Feed <= 2.3.2 versions. The vulnerability has a CVSS score of 7.1 and was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-39507). The vulnerability was last modified on [cveModifiedAt](https://nvd.nist.gov/vuln/detail/CVE-2026-39507).
CVE-2026-23970 is a HIGH severity Unauthenticated Cross Site Scripting (XSS) vulnerability in Redirection for Contact Form 7 plugin versions <= 3.2.8. The vulnerability has a CVSS score of 7.1.
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.1.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to create and exe [truncated]
A missing authorization vulnerability in the Visualizer: Tables and Charts Manager for WordPress plugin allows authenticated attackers with Subscriber-level access to create arbitrary chart posts and access or modify chart data belonging to other users. The vulnerability stems from missing capability checks on the renderChartPages() and uploadData() functions, which are invoked by AJAX actions without cur [truncated]
CVE-2026-24573 is a medium-severity stored cross-site scripting issue in the Visualizer WordPress plugin from Themeisle, affecting versions before 4.0.0. Because the flaw is stored XSS, malicious input can be saved and later rendered in a page context, creating risk for users who view the affected content. The NVD record lists the issue as Deferred and links to a Patchstack reference for the affected plug [truncated]