PatchSiren

Very Good Plugins CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Very Good Plugins CVE published 2026-09-07

CVE-2026-14444

The WP Fusion (Pro) plugin for WordPress has a Privilege Escalation vulnerability in all versions up to, and including, 3.47.13. This is due to insufficient authorization checks on the role parameter in the ThriveCart Auto Login handler's thrivecart() function. Authenticated attackers with Subscriber-level access and above, who possess the access_key, can create a new user account with administrator privi [truncated]