PatchSiren

tidevapps CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH tidevapps CVE published 2026-04-08

CVE-2026-4808

The Gerador de Certificados – DevApps plugin for WordPress has a vulnerability allowing arbitrary file uploads due to missing file type validation in the moveUploadedFile() function up to version 1.3.6. This vulnerability affects WordPress sites using the Gerador de Certificados – DevApps plugin, particularly those with Administrator-level access and above. The vulnerability's impact includes potential re [truncated]