PatchSiren

WordPress.org CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL WordPress.org CVE published 2026-07-27

CVE-2026-13597

The CVE-2026-13597 vulnerability in the 微信二维码登陆 WordPress plugin through version 1.3 allows an unauthenticated attacker to forge a login event for any existing username, read the login code, and redeem it through an unauthenticated AJAX action to log in as that user, including an administrator, without a password. This is due to the plugin's improper validation of WeChat webhook requests, as its signature [truncated]

HIGH WordPress.org CVE published 2026-07-20

CVE-2026-13142

The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 is vulnerable to brute-force attacks due to the lack of rate limiting and attempt lockout on its passwordless email one-time-password verification. The short numeric codes are stored in plaintext, allowing attackers who know a registered email address to brute-force the code and gain unauthorized access to user accounts, incl [truncated]

Review WordPress.org CVE published 2026-07-14

CVE-2026-12583

The CVE record for CVE-2026-12583 was published on 2026-07-14T06:17:05.900Z and has not been modified since then. This vulnerability affects the Newsletters WordPress plugin before version 4.15, allowing unauthenticated attackers to inject a PHP object and execute code on the server. Users of the Newsletters WordPress plugin before version 4.15 should be aware of this vulnerability and take steps to mitig [truncated]

Review WordPress.org CVE published 2026-07-14

CVE-2025-15665

The Ultimate Before After Image Slider & Gallery WordPress plugin before version 4.7.1 has a vulnerability that allows users with administrator-level access to store scripts that execute in visitors' browsers when they load pages displaying the BEAF Slider widget. This issue arises because the plugin does not escape the value of the BEAF Slider widget's shortcode field before outputting it on the front en [truncated]

LOW WordPress.org CVE published 2026-06-12

CVE-2026-9269

CVE-2026-9269 is a Stored Cross-Site Scripting (XSS) vulnerability in the Secure Copy Content Protection and Content Locking WordPress plugin before version 5.1.5. The plugin does not properly sanitize and escape some of its settings, potentially allowing high-privilege users, such as administrators, to perform Stored XSS attacks even when the unfiltered_html capability is disallowed (for example, in a mu [truncated]

MEDIUM WordPress.org CVE published 2026-03-31

CVE-2026-3191

The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.12. This is due to missing or incorrect nonce validation on the 'minify_html_menu_options' function. The vulnerability allows unauthenticated attackers to update plugin settings via a forged request if they can trick a site administrator into performing an action such as clicking on a [truncated]