PatchSiren

wordplus CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM wordplus CVE published 2026-09-16

CVE-2026-18555

The Better Messages plugin for WordPress has a reflected XSS vulnerability via the 'icn' parameter in versions up to 2.15.22. This allows unauthenticated attackers to inject web scripts if they can trick a user into clicking a link. The vulnerability has a CVSS score of 6.1 and a severity of MEDIUM. Defenders should prioritize verifying exposure of Better Messages plugin versions up to 2.15.22 and assess [truncated]