PatchSiren

umarbajwa CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH umarbajwa CVE published 2026-08-01

CVE-2026-15052

The MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Form Field Values in all versions up to, and including, 4.3.3. This vulnerability is caused by insufficient input sanitization and output escaping, allowing unauthenticated attackers to inject arbitrary web scripts. The technical impact of this vulnerability is tha [truncated]

MEDIUM umarbajwa CVE published 2026-07-16

CVE-2026-12409

The Landing Page Builder – Coming Soon page, Maintenance Mode, Lead Page, WordPress Landing Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery. This is due to missing or incorrect nonce validation on the ulpb_admin_ajax function. The vulnerability allows unauthenticated attackers to create, update, retitle, or change the post status, slug, and type of arbitrary posts and write ULPB_DAT [truncated]