PatchSiren

WordPress CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited WordPress CVE published 2026-09-25

CVE-2026-87902

CVE-2026-87902 is a remote file inclusion vulnerability in WordPress Core with known exploitation in the wild. The vulnerability allows attackers to include remote files, potentially leading to remote code execution. System administrators and security teams should prioritize patching, especially for internet-exposed installations. The scope of exploitation and impact require verification from official sou [truncated]

MEDIUM WordPress CVE published 2026-09-02

CVE-2025-15481

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-02T15:17:36.320Z and has not been modified since then. The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all stored subscriber emails. This vulnerability allows unauthorized access to sensitive email data, potentially leading to priva [truncated]

MEDIUM WordPress CVE published 2026-09-02

CVE-2026-19704

The Comments WordPress plugin before 7.6.66 does not validate user input properly, allowing unauthenticated SQL injection attacks. This vulnerability enables attackers to read comments they shouldn't see, including those awaiting moderation, marked as spam or trashed, and on private and draft posts. Defenders should assess their exposure and prioritize verification and remediation efforts to prevent unaut [truncated]

Review WordPress CVE published 2026-08-31

CVE-2026-77013

The 爱采集数据采集和发布插件 WordPress plugin through 1.0.0 does not restrict which of its handler methods a request may invoke, and performs no capability or nonce check on them. This vulnerability allows unauthenticated users to create WordPress user accounts and taxonomy terms, potentially leading to unauthorized access and content modification. Affected WordPress installations should prioritize updating or mitiga [truncated]

HIGH WordPress CVE published 2026-08-19

CVE-2026-14334

The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthenticated attackers to upload a file that bypasses the Booking calendar, Appointment Booking System WordPress plugin through 3.2.36's script-stripping and executes arbitrary JavaScript when the SVG is opened, including in the session of an administrator who reviews [truncated]

HIGH WordPress CVE published 2026-08-17

CVE-2026-65640

WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. This requires Imagick and Ghostscript to be in use on the server and a malicious user with the `upload_files` capability. The issue affects all versions of WordPress, and a fix has been released in version 7.0.4, backported to all branches back to 4.7. Administrators of [truncated]

HIGH WordPress CVE published 2026-08-16

CVE-2026-19728

The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is entitled to a customer-uploaded file before serving it, allowing unauthenticated users who obtain a file's stored name to retrieve it. The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 writes a deny-all rule into its upload directories, so the disclosure o [truncated]

MEDIUM WordPress CVE published 2026-08-16

CVE-2026-15384

The Manual Image Crop WordPress plugin before 1.15 does not perform capability checks or nonce verification for authenticated AJAX actions that crop attachment images. This vulnerability allows a subscriber-level user to supply an arbitrary attachment ID and overwrite the generated intermediate-size image and mutate stored metadata, regardless of who owns the media. The issue is a cross-user integrity/def [truncated]

HIGH WordPress CVE published 2026-08-07

CVE-2026-64638

CVE-2026-64638 is a pre-auth reflected XSS vulnerability in WordPress affecting all versions. The vulnerability can be escalated to RCE under certain conditions with successful social engineering and explicit interaction by the target victim. WordPress site administrators, users, and security teams should be aware of this vulnerability and take necessary actions to mitigate it. The CVE record was publishe [truncated]

HIGH WordPress CVE published 2026-07-28

CVE-2026-45293

A vulnerability in WordPress Coding Standards, a set of PHP_CodeSniffer rules, could allow arbitrary command execution on the scanning host when running PHPCS with WordPressCS over untrusted PHP. This issue affects CI pipelines and developers reviewing third-party code. The vulnerability exists in versions from 0.14.1 until 3.4.1, specifically in the WordPress.WP.EnqueuedResourceParameters sniff. The issu [truncated]

MEDIUM WordPress CVE published 2026-07-27

CVE-2026-12982

The Document Gallery WordPress plugin before 5.1.1 has a Reflected Cross-Site Scripting vulnerability. This issue allows unauthenticated attackers to inject malicious scripts into the response of an AJAX action. The vulnerability can be exploited against unauthenticated users, potentially leading to unauthorized access or malicious script execution. Users of the plugin should be aware of this vulnerabilit [truncated]

MEDIUM WordPress CVE published 2026-07-16

CVE-2026-11866

The Appointment Booking Plugin WordPress plugin before 5.6.3 does not validate a CSRF nonce on several state-changing actions handled by its central request dispatcher. This allows attackers to perform privileged actions, such as overwriting the booking-form configuration or disconnecting the connected payment gateway, via Cross-Site Request Forgery against a logged-in administrator. The vulnerability aff [truncated]

Review WordPress CVE published 2026-07-14

CVE-2026-11563

The CVE record for CVE-2026-11563 was published on 2026-07-14T06:16:48.873Z and has not been modified since then. The NVD entry is currently marked as Received. This vulnerability affects the Word Count and Social Shares WordPress plugin through version 1.0, allowing any authenticated user to delete arbitrary files due to lack of validation, authorization, and CSRF checks. Successful exploitation could le [truncated]

HIGH Wordpress CVE published 2026-05-16

CVE-2021-47979

CVE-2021-47979 describes an authenticated arbitrary file deletion issue in the WordPress plugin Backup and Restore 1.0.3. According to the supplied CVE description and NVD data, an attacker can send crafted POST requests to admin-ajax.php and manipulate the file_name and folder_name parameters to delete files from the WordPress installation directory. Because file deletion can damage site availability and [truncated]

MEDIUM Wordpress CVE published 2026-05-16

CVE-2021-47975

CVE-2021-47975 describes a stored cross-site scripting issue in WP Learn Manager 1.1.2. The supplied record says attacker-supplied content in the fieldtitle parameter can be posted to the jslm_fieldordering page and later execute in an administrator’s browser when the field ordering interface is viewed.

MEDIUM Wordpress CVE published 2026-05-16

CVE-2021-47957

CVE-2021-47957 describes a stored cross-site scripting issue in the Cookie Law Bar WordPress plugin version 1.2.1. An authenticated attacker who can submit the plugin’s Bar Message content may store malicious script that later runs in the browsers of site visitors, creating risk to sessions and data shown in the affected page.

MEDIUM Wordpress CVE published 2026-05-16

CVE-2020-37233

CVE-2020-37233 describes a persistent cross-site scripting issue in the WordPress BuddyPress plugin, version 6.2.0. The supplied record indicates that an authenticated attacker with moderator privileges can place malicious script content into wp:html blocks via the figure parameter, and that the payload can execute when an administrator or other privileged user previews or views the affected content. Beca [truncated]

MEDIUM Wordpress CVE published 2026-05-10

CVE-2022-50961

CVE-2022-50961 affects the WordPress IP2Location Country Blocker plugin 2.26.7 and is described as a stored cross-site scripting issue in the Frontend Settings interface. An authenticated user can place malicious JavaScript in the Display page settings URL field, and the script may execute when an administrator or other authenticated user opens the plugin settings page. The supplied NVD record classifies [truncated]

MEDIUM Wordpress CVE published 2026-05-10

CVE-2022-50960

CVE-2022-50960 covers a reflected cross-site scripting issue in the WordPress plugin International Sms For Contact Form 7 Integration version 1.2. The supplied description says attacker-controlled input in the page parameter of class-sms-log-display.php can be used to execute arbitrary JavaScript in an administrator’s browser.

MEDIUM Wordpress CVE published 2026-05-10

CVE-2022-50959

CVE-2022-50959 describes a reflected cross-site scripting issue in the WordPress Contact Form Builder plugin, version 1.6.1. The vulnerable behavior is tied to the form_id parameter in code_generator.php, where an attacker can supply a crafted URL that causes arbitrary JavaScript to run in a victim’s browser. Because the issue is unauthenticated and browser-triggered, the main risk is session theft, accou [truncated]

MEDIUM Wordpress CVE published 2026-05-10

CVE-2022-50958

CVE-2022-50958 describes a reflected cross-site scripting issue in the WordPress Jetpack plugin, specifically at the grunion-form-view.php endpoint. The source record states that Jetpack 9.1 can be abused by unauthenticated attackers who manipulate the post_id parameter to inject script content that executes in a victim’s browser. Because this is a browser-side issue, the main exposure is session theft, c [truncated]

MEDIUM Wordpress CVE published 2026-05-10

CVE-2022-50956

CVE-2022-50956 is an unauthenticated local file read affecting WordPress plugin amministrazione-aperta 3.7.3. The supplied record says insufficient validation of the open GET parameter in dispatcher.php lets an attacker supply file paths and read sensitive files accessible to the web server. Any deployment still using the plugin should treat this as a serious exposure risk because file disclosure can reve [truncated]

MEDIUM Wordpress CVE published 2026-05-10

CVE-2022-50955

CVE-2022-50955 affects the WordPress Curtain plugin 1.0.2 and is described as a cross-site request forgery issue that can let an attacker toggle site maintenance mode by inducing an authenticated administrator to submit a forged request. The supplied corpus ties the issue to missing nonce validation on the options-general.php page and rates it Medium severity (CVSS 5.3).

MEDIUM WordPress CVE published 2026-05-10

CVE-2022-50954

CVE-2022-50954 is a local file inclusion flaw in the WordPress plugin cab-fare-calculator version 1.0.3. An unauthenticated attacker can manipulate the controller parameter in tblight.php to traverse paths outside the intended controllers directory and include unintended files. In practical terms, this can expose sensitive local files on the server and may also enable file inclusion behavior beyond normal [truncated]

MEDIUM WordPress CVE published 2026-05-10

CVE-2022-50947

CVE-2022-50947 is a stored cross-site scripting issue in the WordPress plugin Testimonial Slider and Showcase 2.2.6. According to the supplied record, an authenticated editor can place malicious script into the testimonial title field because the post_title parameter is not properly sanitized. When affected content is viewed, the script can execute in a browser, creating a risk of session abuse and other [truncated]

MEDIUM Wordpress CVE published 2026-05-10

CVE-2021-47951

CVE-2021-47951 describes a stored cross-site scripting issue in WordPress Picture Gallery 1.4.2. An authenticated attacker can place malicious script content in the plugin’s Access Control settings via the Edit Content URL field, where it is stored and later executed when the affected functionality is used. The main security impact is browser-side compromise of other users’ sessions or credentials, especi [truncated]

MEDIUM Wordpress CVE published 2026-05-10

CVE-2021-47948

CVE-2021-47948 affects the WordPress GetPaid plugin 2.4.6 and allows authenticated HTML injection through the Help Text field in payment forms. Because the content is stored and later rendered in the browser, malicious markup can execute when the form is viewed, which raises the risk of stored cross-site scripting behavior.

CRITICAL Wordpress CVE published 2026-05-10

CVE-2021-47940

CVE-2021-47940 describes an unauthenticated arbitrary file upload issue in the WordPress plugin Download From Files version 1.48 and earlier. The vulnerable AJAX upload flow can be abused through the admin-ajax.php endpoint by manipulating the allowExt parameter to bypass file-type restrictions and place attacker-controlled files in the web root. Because the disclosed behavior includes uploading executabl [truncated]

CRITICAL WordPress CVE published 2026-05-10

CVE-2021-47933

CVE-2021-47933 is a critical unauthenticated arbitrary file upload issue affecting the MStore API WordPress plugin, described as allowing attackers to POST malicious files to a REST API endpoint and potentially reach remote code execution on vulnerable servers. The supplied NVD record maps the issue to CWE-306, and the record’s references point to the plugin page plus external VulnCheck and Exploit-DB mat [truncated]

MEDIUM Wordpress CVE published 2026-05-10

CVE-2021-47924

CVE-2021-47924 describes a stored cross-site scripting issue in Ultimate Product Catalog 5.8.2. According to the supplied record, an authenticated attacker can submit a malicious value through the price parameter and have it execute when the affected product is viewed. The CVE entry was published and modified on 2026-05-10 in the supplied timeline.