AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T09:17:01.540Z and has not been modified since then. The Fluent Forms plugin for WordPress, up to and including version 6.2.8, is vulnerable to Reflected Cross-Site Scripting via the 'param' due to insufficient input sanitization and output escaping. This vulnerability allows unauthenticated attac [truncated]
The Fluent Forms plugin for WordPress, specifically versions up to and including 6.2.8, is vulnerable to Insecure Direct Object Reference (IDOR) attacks. This vulnerability is caused by a lack of proper validation on user-controlled keys, specifically the 'transaction' parameter. As a result, unauthenticated attackers can brute-force valid transaction hashes and gain access to sensitive payment receipt da [truncated]
CVE-2026-57715 is a Reflected XSS vulnerability in Fluent CRM, a WordPress plugin. The vulnerability is caused by improper neutralization of input during web page generation, potentially leading to unauthorized actions or data theft. Users of Fluent CRM plugin versions up to 3.1.7 should prioritize patching this HIGH severity vulnerability. The CVE record was published on 2026-07-13T10:16:38.737Z and has [truncated]
The Fluent Forms plugin for WordPress is vulnerable to incorrect authorization via the 'subscription_id' parameter in versions up to, and including, 6.2.1. This is due to insufficient ownership authorization checks in the payment cancellation AJAX flow. This makes it possible for authenticated attackers, with subscriber-level access and above, to submit cancellation requests for other users' subscriptions [truncated]
CVE-2026-42655 is a MEDIUM severity vulnerability found in the Best Payments Plugin for WP, affecting versions up to and including 4.6.19. This vulnerability allows unauthenticated attackers to bypass payment security measures. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 5.9. The vulnerability was published on [cvePublishedAt] and last modified on [cveModifiedAt].