PatchSiren

wp.insider CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH wp.insider CVE published 2026-08-06

CVE-2026-66712

CVE-2026-66712 is an unauthenticated broken access control vulnerability in Simple Membership plugin version 4.7.8 or earlier. The vulnerability has a CVSS score of 7.5 and is considered HIGH severity. Administrators and users of Simple Membership plugin version 4.7.8 or earlier should be aware of this vulnerability and take necessary actions to prevent potential unauthorized access. This includes reviewi [truncated]

HIGH wp.insider CVE published 2026-06-15

CVE-2026-52692

CVE-2026-52692 is a HIGH severity vulnerability (CVSS Score: 7.5) in the Affiliates Manager plugin versions <= 2.9.50. The vulnerability allows unauthenticated sensitive data exposure. The CVE was published on 2026-06-15T21:17:23.853Z and last modified on 2026-06-15T21:24:32.790Z.

MEDIUM wp.insider CVE published 2026-06-15

CVE-2026-42663

CVE-2026-42663 is a MEDIUM severity Unauthenticated Cross Site Scripting (XSS) vulnerability in Simple Membership plugin versions <= 4.7.2. The vulnerability was published on [cvePublishedAt] and last modified on [cveModifiedAt]. The CVSS score for this vulnerability is 6.5.

HIGH wp.insider CVE published 2026-06-15

CVE-2026-34886

CVE-2026-34886 is a HIGH severity vulnerability with a CVSS score of 7.5. It is an Unauthenticated Broken Access Control issue affecting Simple Membership plugin versions <= 4.7.1.