PatchSiren

WPFunnels Team CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM WPFunnels Team CVE published 2026-10-05

CVE-2026-104386

A Missing Authorization vulnerability in WPFunnels Team WP VR wpvr allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP VR: from n/a through 9.1.3. The vulnerability could lead to potential unauthorized access and exploitation of incorrectly configured access control security levels in WordPress installations with the vulnerable WP VR plugin. Defenders should asse [truncated]

MEDIUM WPFunnels Team CVE published 2026-05-21

CVE-2026-27349

CVE-2026-27349 is a medium-severity information disclosure issue affecting the Mail Mint WordPress plugin, with reported impact through version 1.19.5. The available data indicates that the flaw can expose embedded sensitive system information to an unauthorized control sphere, which may increase the risk of follow-on attacks if exposed data is reused elsewhere. The CVSS vector shows network attackability [truncated]