These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-66448 is a Cross Site Scripting (XSS) vulnerability in Gallery PhotoBlocks versions <= 1.3.3. Contributor-level access is required to exploit this issue. This vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. Users of Gallery PhotoBlocks versions <= 1.3.3 should review and apply updates to mitigate this vulnerability. The vulnerability affects Gallery PhotoBlocks, a popular plugin u [truncated]
CVE-2026-42688 is a Subscriber Cross Site Scripting (XSS) vulnerability in Modula Image Gallery versions <= 2.14.23. The vulnerability has a CVSS score of 6.5, indicating a MEDIUM severity level. The CVE was published on 2026-06-15T21:16:56.990Z and last modified on 2026-06-15T21:24:32.790Z. For more information, refer to the [CVE-2026-42688 CVE record](resourceLinkAnnotations.cve-org) and [CVE-2026-42688 [truncated]
CVE-2026-39489 is a medium-severity vulnerability (CVSS Score: 4.4) affecting the Download Monitor plugin for WordPress, specifically versions up to 5.1.9. The issue allows an author to download arbitrary files. The vulnerability was published on [cvePublishedAt] and last modified on [cveModifiedAt].
CVE-2026-39481 is a HIGH-severity vulnerability in Modula Image Gallery plugin versions up to 2.14.18. The issue is an Author PHP Object Injection vulnerability. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 7.2.
A Missing Authorization vulnerability in the WP Chill RSVP and Event Management WordPress plugin allows attackers to exploit incorrectly configured access control security levels. The vulnerability affects all versions from n/a through 2.7.16. The issue was published in the CVE database on May 25, 2026, with a subsequent modification on May 26, 2026. The vulnerability is classified as CWE-862 (Missing Aut [truncated]
CVE-2026-27424 is a missing-authorization / broken-access-control issue reported for the WordPress Image Photo Gallery Final Tiles Grid plugin through version 3.6.11. The NVD record maps it to CWE-862 and assigns a CVSS 3.1 score of 4.3 (Medium), with a network-reachable, low-privilege attack path and limited confidentiality impact in the supplied vector. The source data points to a Patchstack advisory fo [truncated]
A Missing Authorization vulnerability was discovered in the Revive.so plugin for WordPress, affecting versions from n/a through 2.0.7. This issue, tracked as CVE-2026-39561, has a CVSS score of 5.3 and is classified as MEDIUM severity. The vulnerability is related to Exploiting Incorrectly Configured Access Control Security Levels. The CVE record was published on 2026-04-08T09:16:27.210Z and last modified [truncated]
The CVE-2026-39536 vulnerability is an Exposure of Sensitive System Information to an Unauthorized Control Sphere issue in the WP Chill RSVP and Event Management plugin. This issue allows for the retrieval of embedded sensitive data and affects versions from n/a through 2.7.16. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Users of the WP Chill RSVP and Event Management p [truncated]
A vulnerability was found in Image Photo Gallery Final Tiles Grid, an Authorization Bypass Through User-Controlled Key issue that allows for Exploiting Incorrectly Configured Access Control Security Levels. This vulnerability affects Image Photo Gallery Final Tiles Grid from n/a through version 3.6.11. The issue has a CVSS score of 2.7 and is classified as LOW severity. Users of Image Photo Gallery Final [truncated]
A SQL Injection vulnerability was discovered in the Download Monitor plugin for WordPress, affecting versions from n/a through 5.1.8. This issue allows for Blind SQL Injection attacks. The vulnerability arises from improper neutralization of special elements used in an SQL command. Users of the Download Monitor plugin for WordPress, particularly those with versions 5.1.8 or earlier, should be aware of thi [truncated]