PatchSiren

TMS CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL TMS CVE published 2026-06-17

CVE-2026-49080

CVE-2026-49080 is a critical vulnerability in the wpDataTables plugin for WordPress. The vulnerability, which has a CVSS score of 9.3, allows unauthenticated attackers to inject malicious SQL code. This could potentially lead to unauthorized access to sensitive data. The vulnerability was published on June 17, 2026, and immediately gained attention due to its severity. Users of wpDataTables versions less [truncated]

HIGH TMS CVE published 2026-06-15

CVE-2026-48889

A high-severity vulnerability, CVE-2026-48889, was discovered in the Amelia plugin, affecting versions up to 2.3. This vulnerability allows for subscriber privilege escalation, posing a significant risk to WordPress sites using the affected plugin versions.

MEDIUM TMS CVE published 2026-06-15

CVE-2026-40795

A Subscriber Broken Access Control vulnerability was found in the Amelia plugin versions <= 2.2. This issue has a CVSS score of 6.5, indicating a MEDIUM severity level. The vulnerability was published on [cvePublishedAt] and last modified on [cveModifiedAt].