PatchSiren

wp-buy CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH wp-buy CVE published 2026-06-15

CVE-2026-52702

CVE-2026-52702 is a high-severity Unauthenticated Cross Site Scripting (XSS) vulnerability affecting SEO Redirection plugin versions <= 9.17. The vulnerability has a CVSS score of 7.1 and is considered HIGH severity. It was published on [cvePublishedAt] and last modified on [cveModifiedAt].

HIGH wp-buy CVE published 2026-04-04

CVE-2026-2936

The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_title' parameter in all versions up to, and including, 8.4 due to insufficient input sanitization and output escaping. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever an admin user accesses the Traffic by Title sect [truncated]