PatchSiren

WP Swings CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH WP Swings CVE published 2026-07-13

CVE-2026-57709

CVE-2026-57709 is a Path Traversal vulnerability in Membership For WooCommerce. The vulnerability has a CVSS score of 8.6 and is classified as HIGH severity. The issue affects Membership For WooCommerce from n/a through <= 3.1.0. This vulnerability allows attackers to traverse the file system, potentially leading to arbitrary file deletion or other security issues. Users of Membership For WooCommerce, par [truncated]

HIGH WP Swings CVE published 2026-07-13

CVE-2026-57407

A Server-Side Request Forgery (SSRF) vulnerability was discovered in PDF Generator for WordPress. The issue affects PDF Generator for WordPress versions from n/a through 1.6.2. The vulnerability has a CVSS score of 7.2 and is classified as HIGH. This SSRF issue allows an attacker to make the server perform unintended requests, potentially leading to unauthorized access or data breaches. Users should be aw [truncated]

MEDIUM WP Swings CVE published 2026-07-13

CVE-2026-57400

A Missing Authorization vulnerability exists in WP Swings Event Tickets Manager for WooCommerce, affecting versions from n/a through <= 1.5.5. This issue allows for Exploiting Incorrectly Configured Access Control Security Levels, with a CVSS score of 6.5 and severity rated as MEDIUM. The vulnerability has not been modified since its publication on 2026-07-13T10:16:33.567Z. Users of Event Tickets Manager [truncated]

HIGH WP Swings CVE published 2026-06-26

CVE-2026-56061

CVE-2026-56061 is a HIGH-severity vulnerability in Subscriptions for WooCommerce plugin versions <= 1.9.5. This vulnerability allows unauthenticated broken access control, potentially enabling attackers to manipulate subscriptions. The CVSS score for this vulnerability is 7.5. The vulnerability was published on June 26, 2026, and last modified on June 29, 2026. Users of affected versions should apply patc [truncated]

HIGH WP Swings CVE published 2026-06-15

CVE-2026-49110

CVE-2026-49110 is a HIGH severity vulnerability in Upsell Order Bump Offer for WooCommerce plugin versions up to 3.1.4. This vulnerability is caused by unauthenticated broken authentication, allowing attackers to manipulate prices. The CVSS score for this vulnerability is 7.5, indicating a high level of severity. The vulnerability was published on [cvePublishedAt] and last modified on [cveModifiedAt].

HIGH WP Swings CVE published 2026-06-15

CVE-2026-34898

CVE-2026-34898 is a HIGH severity vulnerability in Event Tickets Manager for WooCommerce plugin versions <= 1.5.3. The vulnerability is caused by Unauthenticated Broken Access Control, with a CVSS score of 7.5. The vulnerability was published on [cvePublishedAt] and last modified on [cveModifiedAt].

CRITICAL WP Swings CVE published 2026-05-20

CVE-2026-45444

CVE-2026-45444 is a critical unrestricted upload vulnerability in the WP Swings Gift Cards For WooCommerce Pro WordPress plugin, affecting versions through 4.2.6. Based on the published record, the issue is rated CVSS 3.1 10.0 and can be triggered remotely without user interaction. Because dangerous file types may be accepted, affected sites should treat this as a high-risk path to malicious file placemen [truncated]