PatchSiren

WebFacing CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM WebFacing CVE published 2026-09-27

CVE-2026-84069

CVE-2026-84069 is a Local File Inclusion vulnerability in the WebFacing WordPress plugin before version 5.4. The plugin does not restrict access to one of its bundled scripts and does not validate a user-supplied path before using it to include a local file, allowing unauthenticated users to perform Local File Inclusion. This vulnerability has a CVSS score of 5.3 and a severity of MEDIUM.