PatchSiren

wpmudev CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL wpmudev CVE published 2026-09-05

CVE-2026-83627

The Hummingbird – Speed Optimization, Caching, Minify, Compress & CDN plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 3.21.0 via the log_msg() function in core/modules/class-page-cache.php. The page-cache debug log is written to wp-content/wphb-logs/page-caching-log.php, a directly web-accessible PHP file that is supposed to be protected by a leading '<?ph [truncated]

HIGH wpmudev CVE published 2026-08-06

CVE-2026-18325

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Forged Upload Record. This vulnerability, affecting all versions up to and including 1.56.1, stems from insufficient input sanitization and output escaping. An unauthenticated attacker can exploit this weakness to inject arbitrary web scripts, which will execute whe [truncated]

MEDIUM wpmudev CVE published 2026-04-08

CVE-2026-2263

The Hustle – Email Marketing, Lead Generation, Optins, Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hustle_module_converted' AJAX action in all versions up to, and including, 7.8.10.2. This vulnerability allows unauthenticated attackers to forge conversion tracking events for any Hustle module, including draft modules that are nev [truncated]