These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The AI Builder WordPress plugin before 2.7.8 does not sanitise custom JavaScript saved against a post before echoing it inside a script tag on the front end, allowing users with contributor level access and above to store arbitrary JavaScript that will execute in the browser of anyone who views the post, including the editor or administrator who reviews it.
The Backup Migration WordPress plugin before 2.1.7 does not properly restrict a post-restore automatic login mechanism, allowing a user who administers one site of a multisite network to obtain a long-lived authenticated session as an administrator of another site in the same network, without credentials and bypassing two-factor authentication. This vulnerability affects administrators of multisite WordPr [truncated]
The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before version 1.1.8 does not prevent unauthenticated users from obtaining a valid nonce for its file-deletion routine. This allows anonymous attackers to delete files staged in its upload directory and irreversibly destroy customers' pending order attachments. Affected product deployments should be identified and prioritized for upda [truncated]
The SEO Redirection Plugin for WordPress, version before 9.19, contains a vulnerability allowing logged-in users, including subscribers, to read the site's configured 301 redirect rules. This is due to a lack of capability checks in an authenticated AJAX action. The vulnerability has a CVSS score of 5.4 and is considered medium severity. WordPress administrators and users with the SEO Redirection Plugin i [truncated]
The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to the requesting vendor, allowing an authenticated vendor (Store Owner and above) to view, take over, permanently delete, or modify any other vendor's store on the marketplace. This vulnerability affects users with authenticated vendor access, particularly Store Owner and above roles. The [truncated]
The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions during CSV import, allowing a user holding only the user-creation capability to create an administrator account and to overwrite an existing administrator's password or email. This vulnerability affects WordPress users with administrator accounts and users with [truncated]
The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads and displays during a CSV import, allowing high-privileged users to read arbitrary files on the server. This issue was reported by Wpscan. The vulnerability could allow an attacker to access sensitive information on the server. Defenders should verify plugin version and file access control [truncated]
The CVE-2026-13597 vulnerability in the 微信二维码登陆 WordPress plugin through version 1.3 allows an unauthenticated attacker to forge a login event for any existing username, read the login code, and redeem it through an unauthenticated AJAX action to log in as that user, including an administrator, without a password. This is due to the plugin's improper validation of WeChat webhook requests, as its signature [truncated]
The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 is vulnerable to brute-force attacks due to the lack of rate limiting and attempt lockout on its passwordless email one-time-password verification. The short numeric codes are stored in plaintext, allowing attackers who know a registered email address to brute-force the code and gain unauthorized access to user accounts, incl [truncated]
The CVE record for CVE-2026-12583 was published on 2026-07-14T06:17:05.900Z and has not been modified since then. This vulnerability affects the Newsletters WordPress plugin before version 4.15, allowing unauthenticated attackers to inject a PHP object and execute code on the server. Users of the Newsletters WordPress plugin before version 4.15 should be aware of this vulnerability and take steps to mitig [truncated]
The Ultimate Before After Image Slider & Gallery WordPress plugin before version 4.7.1 has a vulnerability that allows users with administrator-level access to store scripts that execute in visitors' browsers when they load pages displaying the BEAF Slider widget. This issue arises because the plugin does not escape the value of the BEAF Slider widget's shortcode field before outputting it on the front en [truncated]
CVE-2026-9269 is a Stored Cross-Site Scripting (XSS) vulnerability in the Secure Copy Content Protection and Content Locking WordPress plugin before version 5.1.5. The plugin does not properly sanitize and escape some of its settings, potentially allowing high-privilege users, such as administrators, to perform Stored XSS attacks even when the unfiltered_html capability is disallowed (for example, in a mu [truncated]
The Minify HTML plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.12. This is due to missing or incorrect nonce validation on the 'minify_html_menu_options' function. The vulnerability allows unauthenticated attackers to update plugin settings via a forged request if they can trick a site administrator into performing an action such as clicking on a [truncated]