PatchSiren

WP Media CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM WP Media CVE published 2026-05-27

CVE-2026-49045

A Missing Authorization vulnerability (CWE-862) in the Adminimize WordPress plugin allows authenticated users with low privileges to exploit incorrectly configured access control security levels. The vulnerability affects all versions from n/a through 1.11.11. The issue was published to the CVE List on 2026-05-27 and carries a CVSS 3.1 score of 4.3 (Medium severity), with an attack vector of Network, Low [truncated]