PatchSiren

trustindex CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM trustindex CVE published 2026-07-11

CVE-2026-11591

The CVE record for CVE-2026-11591 was published on 2026-07-11T07:16:45.073Z and has not been modified since then. The NVD entry is currently . This vulnerability affects the Widgets for Google Reviews plugin for WordPress, specifically versions up to and including 13.3. The vulnerability is due to insufficient input sanitization and output escaping, allowing authenticated attackers with editor-level permi [truncated]

MEDIUM trustindex CVE published 2026-05-02

CVE-2025-14726

The Widgets for Social Photo Feed plugin for WordPress is vulnerable to unauthorized access of data and modification of data due to a missing capability check on the '/trustindex_feed_hook_instagram/troubleshooting' and '/trustindex_feed_hook_instagram/submit-data' REST API endpoints in all versions up to, and including, 1.8. This vulnerability allows unauthenticated attackers to access and update plugin [truncated]