These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The CVE-2026-13597 vulnerability in the 微信二维码登陆 WordPress plugin through version 1.3 allows an unauthenticated attacker to forge a login event for any existing username, read the login code, and redeem it through an unauthenticated AJAX action to log in as that user, including an administrator, without a password. This is due to the plugin's improper validation of WeChat webhook requests, as its signature [truncated]
The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 is vulnerable to brute-force attacks due to the lack of rate limiting and attempt lockout on its passwordless email one-time-password verification. The short numeric codes are stored in plaintext, allowing attackers who know a registered email address to brute-force the code and gain unauthorized access to user accounts, incl [truncated]
The CVE record for CVE-2026-12583 was published on 2026-07-14T06:17:05.900Z and has not been modified since then. This vulnerability affects the Newsletters WordPress plugin before version 4.15, allowing unauthenticated attackers to inject a PHP object and execute code on the server. Users of the Newsletters WordPress plugin before version 4.15 should be aware of this vulnerability and take steps to mitig [truncated]
The Ultimate Before After Image Slider & Gallery WordPress plugin before version 4.7.1 has a vulnerability that allows users with administrator-level access to store scripts that execute in visitors' browsers when they load pages displaying the BEAF Slider widget. This issue arises because the plugin does not escape the value of the BEAF Slider widget's shortcode field before outputting it on the front en [truncated]
CVE-2026-9269 is a Stored Cross-Site Scripting (XSS) vulnerability in the Secure Copy Content Protection and Content Locking WordPress plugin before version 5.1.5. The plugin does not properly sanitize and escape some of its settings, potentially allowing high-privilege users, such as administrators, to perform Stored XSS attacks even when the unfiltered_html capability is disallowed (for example, in a mu [truncated]
The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.12. This is due to missing or incorrect nonce validation on the 'minify_html_menu_options' function. The vulnerability allows unauthenticated attackers to update plugin settings via a forged request if they can trick a site administrator into performing an action such as clicking on a [truncated]