These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Path Traversal (Zip Slip) in all versions up to, and including, 6.0.13 via the extract_zip_file function. This makes it possible for authenticated attackers, with custom-level access and above, to write arbitrary files on the server, potentially leading to remote code execution. The install_app, update_ap [truncated]
A vulnerability was found in the Kirki plugin, affecting versions up to 6.0.13. This issue allows an editor to delete arbitrary files. The vulnerability has a CVSS score of 6.8, indicating a medium severity level. The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H. Users with editor privileges should be aware of this vulnerability and take necessary precautions.
The Tutor LMS Elementor Addons plugin for WordPress has a Missing Authorization vulnerability in all versions up to, and including, 4.0.0. This is due to missing capability checks on the `activate_tutor_free()` and `activate_elementor_free()` functions registered as `admin_action_*` handlers. This makes it possible for authenticated attackers, with Subscriber-level access and above, to activate the Tutor [truncated]
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.0.13 via the 'family' parameter. This makes it possible for authenticated attackers, with editor-level access and above, to delete arbitrary directories on the server, which can result in loss of data and availability. The vulnerability has a CVS [truncated]
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via Stored Quiz Answer Array in all versions up to, and including, 4.0.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This vulnerability allows authenticated attackers with custom-level access and above to append addit [truncated]
CVE-2026-57727 is a HIGH severity vulnerability with a CVSS score of 7.5, described as a Missing Authorization issue in Themeum Kirki kirki, which could allow Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Kirki from n/a through <= 6.0.13. The vulnerability has a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N and is associated with CWE-862. Administrators [truncated]
A CRITICAL SQL Injection vulnerability was discovered in Kirki, a WordPress plugin. The vulnerability, tracked as CVE-2026-57726, has a CVSS score of 9.3 and allows for Blind SQL Injection. The issue affects Kirki from n/a through version 6.0.12. This vulnerability can be exploited by attackers to inject malicious SQL code, potentially leading to unauthorized access to sensitive data. Administrators and u [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-13T10:16:39.200Z and has not been modified since then. This Stored XSS vulnerability in Kirki plugin versions up to 6.0.11 affects users who have not applied patches or mitigations. The vulnerability has a CVSS score of 7.1 and is considered High priority.
A Deserialization of Untrusted Data vulnerability exists in Themeum Kirki, affecting versions from n/a through 6.0.12. This issue allows for Object Injection. The vulnerability has a CVSS score of 9.8 and is classified as CRITICAL. Users should be aware of the potential impact and take necessary precautions to secure their deployments. It is essential to review the official CVE record and NVD details for [truncated]
A vulnerability was found in Themeum Tutor LMS, allowing for authorization bypass through user-controlled keys. This issue, CVE-2026-57694, has a CVSS score of 6.5 and is classified as MEDIUM severity. The vulnerability is caused by incorrectly configured access control security levels, allowing for exploitation. Users of Themeum Tutor LMS, particularly those with version 3.9.13 or earlier, should be awar [truncated]
The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the 'data' parameter in all versions up to, and including, 3.9.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This vulnerability allows authenticated attackers with administrator-level access and above to append a [truncated]
CVE-2026-22332 is a critical vulnerability in Tutor LMS Pro, a popular WordPress plugin. The vulnerability, which has a CVSS score of 9.3, allows unauthenticated attackers to inject malicious SQL code. This could lead to unauthorized access to sensitive data, modification of database contents, and potentially, elevation of privileges. The vulnerability was published on June 17, 2026, and immediately gaine [truncated]
CVE-2026-22330 is an Unauthenticated Local File Inclusion vulnerability in Right Way theme versions <= 4.0. The CVSS score is 8.1, indicating a HIGH severity level. This vulnerability allows unauthenticated attackers to include local files, potentially leading to code execution. Users should prioritize patching due to the high CVSS score and potential for code execution.
CVE-2026-22329 is a high-severity Unauthenticated Cross Site Scripting (XSS) vulnerability in Skillate versions <= 1.2.10. This vulnerability has a CVSS score of 7.1 and is considered HIGH severity. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of affected versions should take immediate action to mitigate the risk. The vulnerability allows attackers to inject m [truncated]
CVE-2026-40743 is a MEDIUM severity vulnerability (CVSS Score: 6.5) in Tutor LMS plugin versions <= 3.9.7. The vulnerability is caused by unauthenticated broken access control. The CVE was published on 2026-06-15T21:16:49.003Z and last modified on 2026-06-15T21:24:32.790Z.
CVE-2026-8096 affects the Kirki – Freeform Page Builder, Website Builder & Customizer WordPress plugin in versions up to and including 6.0.6. The issue is an authorization bypass caused by insufficient verification that a user is allowed to perform the action. As disclosed, authenticated attackers with subscriber-level access and above can view Kirki frontend forms and read stored visitor submission data, [truncated]
CVE-2026-8073 is a high-severity flaw in the Kirki WordPress plugin that can let an unauthenticated attacker trigger arbitrary file deletion, with the impact limited to paths under the WordPress uploads base directory. The issue is tied to insufficient file path validation and a missing capability check in the downloadZIP function. NVD lists the vulnerability as deferred, while Wordfence references the af [truncated]
A vulnerability was found in Qubely, a WordPress plugin, which allows for Stored Cross-site Scripting (XSS). This issue affects Qubely versions from n/a through 1.8.14. The vulnerability is caused by improper neutralization of input during web page generation. The CVSS score for this vulnerability is 5.9, with a severity of MEDIUM. Users of Qubely plugin versions up to 1.8.14 should be aware of this vulne [truncated]