PatchSiren

WP Engine CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM WP Engine CVE published 2026-06-15

CVE-2026-49043

CVE-2026-49043 is a MEDIUM severity Unauthenticated Cross Site Request Forgery (CSRF) vulnerability affecting WP Migrate Lite versions up to 2.7.8. The vulnerability has a CVSS score of 4.7. It was published on [cvePublishedAt](https://www.cve.org/CVERecord?id=CVE-2026-49043) and last modified on [cveModifiedAt](https://nvd.nist.gov/vuln/detail/CVE-2026-49043).

HIGH WP Engine CVE published 2026-06-15

CVE-2026-49062

A high-severity Authentication Bypass Using an Alternate Path or Channel vulnerability was discovered in WP Engine Faust.Js, allowing for Password Recovery Exploitation. This issue affects Faust.Js versions from n/a through 1.8.7, with a CVSS score of 8.8.