PatchSiren

WPDeveloper CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH WPDeveloper CVE published 2026-08-06

CVE-2026-61961

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:17:12.950Z and has not been modified since then. This vulnerability affects EmbedPress version 4.5.6 or earlier, allowing unauthenticated Cross Site Scripting (XSS) attacks. The vulnerability enables attackers to inject malicious scripts into web pages, potentially leading to unauthorized acti [truncated]

MEDIUM WPDeveloper CVE published 2026-07-27

CVE-2026-65562

A Cross Site Scripting (XSS) vulnerability was found in the BetterDocs plugin, version 4.6.2 and earlier. The vulnerability is rated as MEDIUM with a CVSS score of 6.5. This issue allows an attacker to inject malicious scripts into the BetterDocs plugin, potentially leading to unauthorized actions or data exposure. Users of the BetterDocs plugin should be aware of this vulnerability and take necessary act [truncated]

HIGH WPDeveloper CVE published 2026-06-15

CVE-2026-48872

CVE-2026-48872 is a HIGH severity vulnerability (CVSS Score: 7.5) in the EmbedPress plugin versions <= 4.5.2. This vulnerability allows unauthenticated sensitive data exposure. The CVE was published on 2026-06-15T21:17:16.670Z and last modified on 2026-06-15T21:24:32.790Z.

MEDIUM WPDeveloper CVE published 2026-06-15

CVE-2026-25440

CVE-2026-25440 is a MEDIUM severity vulnerability (CVSS Score 5.3) affecting Essential Addons for Elementor versions prior to 6.6.0. The vulnerability is characterized as Unauthenticated Broken Access Control.