PatchSiren

theyeti CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM theyeti CVE published 2026-04-08

CVE-2026-5508

The CVE record for CVE-2026-5508 was published on 2026-04-08T07:16:23.367Z and has not been modified since then. The NVD entry is currently Deferred. This vulnerability affects the WowPress plugin for WordPress, specifically versions up to and including 1.0.0. The vulnerability class is Stored Cross-Site Scripting, which allows authenticated attackers with contributor-level access and above to inject arbi [truncated]